Improper Resource Shutdown or Release Affecting dcmtk package, versions <3.6.8-5


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.25% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-DCMTK-13653039
  • published22 Oct 2025
  • disclosed21 Oct 2025

Introduced: 21 Oct 2025

CVE-2022-4981  (opens in a new tab)
CWE-404  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade Debian:13 dcmtk to version 3.6.8-5 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream dcmtk package and not the dcmtk package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit is now public and may be used. Upgrading to version 3.6.8 is sufficient to resolve this issue. The patch is identified as 957fb31e5. Upgrading the affected component is advised.

CVSS Base Scores

version 3.1