RadiAnt DICOM returns with ICSMA-26-218-01, a different flaw from its 2025 update-channel bug. CVE-2026-17264, a heap-based buffer overflow triggered when the viewer opens a DICOM file with crafted JPEG-compressed pixel data.

A heap overflow of this kind usually begins with a mismatch between what a file declares about itself and what it holds. The decoder reads length and dimension fields, reserves a block of memory sized from them, then copies the pixel data in. When the declared size and the real payload disagree, or an internal size calculation wraps, the copy runs past the end of that block into neighboring memory, corrupting structures the program later relies on.

The delivery path is what makes it clinically relevant. A malicious study does not need a special channel; it can arrive the way legitimate imaging does, referred from another facility or pulled from an archive, and land on the very workstation a radiologist reads it on. That workstation sits inside the trusted clinical network, so a foothold there is a foothold in a sensitive place. Memory corruption in a viewer is rarely the end of an attack; it is the opening move.

A DICOM object is a container, and inside it the compressed pixel data is attacker-controlled input the parser has to handle safely. CISA advises updating to 2026.1 and only opening files from trusted sources, though in practice imaging software opens whatever a clinician receives.

The same product had already appeared on the advisory list for an unrelated weakness, and viewers across this category keep drawing memory-safety findings against their image-handling code. Much of that code is mature and fast, written when the decoder's job was to render valid studies quickly rather than withstand a file built to break it. Hardening a parser to treat every field as hostile is slower and less visible than shipping features.

If you write an image decoder, fuzz it with malformed inputs until it stops crashing, then keep fuzzing. The JPEG path inside DICOM is where memory-corruption bugs hide, and this year kept proving it.