CVE-2024-24794: Nih Libdicom

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker would need to induce the vulnerable application to process a malicious DICOM image.The Use-After-Free happens in the `parse_meta_sequence_end()` parsing the Sequence Value Represenations.

Affected products

  • Nih Libdicom: version 1.0.5 only

Published 2024-02-20. Last modified 2026-06-17.