Intel

AIKIDO-2025-10865

itk is vulnerable to Out-of-bounds Read

Out-of-bounds Read Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

60

Medium Risk

This Affects:

PYTHONitk
4.0.0 - 5.4.4
Fixed in 5.4.5

TL;DR

An out-of-bounds read vulnerability exists in the underlying Grassroots DICOM library (GDCM), specifically in the SequenceOfFragments::ReadValue method. The flaw is triggered when the library parses a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored across multiple fragments). Improper bounds checking allows the parser to read beyond the intended memory region, which may lead to application crashes, information disclosure, or other undefined behavior when handling attacker-controlled DICOM files.

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

Background info

itk is vulnerable to Out-of-bounds Read in versions 4.0.0 - 5.4.4.

How to fix this

Upgrade itk library to patch version.