# CVE-2024-22373

## Summary

- **CVE ID:** CVE-2024-22373
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-119
- **Published:** Apr 25, 2024
- **Last Modified:** Sep 10, 2026

## Description

An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

## Affected Products

- Grassroot DICOM — Grassroot DICOM (3.0.23)

## References

- [CNA](https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N5HXUKUJ7SG3TK456SGUWVZ4Z5D7JKOL/)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJA7QWWZWMY4AQFR35EA7S3CFVUTOQYG/)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZJ4IG7EXMSMPHTK5ZFASCW6MHSOVZOE/)
- [CVE](https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1935)
- [CVE](http://www.openwall.com/lists/oss-security/2026/09/10/13)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.58%
- **EPSS Percentile:** 74.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._