From: Étienne Mollier Date: Mon, 8 Jun 2026 17:13:13 +0000 (+0200) Subject: CVE-2026-10194.patch: new: fix CVE-2026-10194. X-Git-Tag: archive/raspbian/3.7.0+really3.7.0-5+rpi1^2~10 X-Git-Url: https://dgit.raspbian.org/%22http://www.example.com/cgi/%22/%22http:/www.example.com/cgi/%22?a=commitdiff_plain;h=4cdc9b713f0821f53958964a6f1caee3d0af5d5e;p=dcmtk.git CVE-2026-10194.patch: new: fix CVE-2026-10194. Closes: #1139181 --- diff --git a/debian/patches/CVE-2026-10194.patch b/debian/patches/CVE-2026-10194.patch new file mode 100644 index 00000000..7dbe7f97 --- /dev/null +++ b/debian/patches/CVE-2026-10194.patch @@ -0,0 +1,67 @@ +Description: Fixed remote heap buffer overflow in dcmqrscp. + Thanks to 'elp3pinill0' for the bug report, detailed + analysis, proof of concept and proposed fix. +Author: Marco Eichelberg +Applied-Upstream: 0f78a4ef6f645ea5530166e445e5436a5de58e75 +Last-Update: 2026-05-04 +Bug: https://support.dcmtk.org/redmine/issues/1206 +Bug-Debian: https://bugs.debian.org/1139181 +Reviewed-By: Étienne Mollier + +diff --git a/dcmqrdb/libsrc/dcmqrdbi.cc b/dcmqrdb/libsrc/dcmqrdbi.cc +index c91116a1c..ee308abe1 100644 +--- a/dcmqrdb/libsrc/dcmqrdbi.cc ++++ b/dcmqrdb/libsrc/dcmqrdbi.cc +@@ -1,6 +1,6 @@ + /* + * +- * Copyright (C) 1993-2025, OFFIS e.V. ++ * Copyright (C) 1993-2026, OFFIS e.V. + * All rights reserved. See COPYRIGHT file for details. + * + * This software and supporting documentation were developed by +@@ -2471,12 +2471,16 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages(StudyDescRec + + DB_IdxInitLoop (&(handle_ -> idxCounter)) ; + while ( DB_IdxGetNext(&(handle_ -> idxCounter), &idxRec) == EC_Normal ) { +- if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) { +- +- StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ; +- StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ; +- StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ; +- } ++ if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) { ++ StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ; ++ StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ; ++ StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ; ++ if (nbimages == MAX_NUMBER_OF_IMAGES) { ++ // too many images in this study, bail out ++ DCMQRDB_ERROR("maximum number of images per study (" << MAX_NUMBER_OF_IMAGES << ") exceeded"); ++ return QR_EC_IndexDatabaseError; ++ } ++ } + } + + /** Sort the StudyArray in order to have the oldest images first +@@ -2563,6 +2567,8 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec + s = matchStudyUIDInStudyDesc (pStudyDesc, StudyUID, + (int)(handle_ -> maxStudiesAllowed)) ; + ++ OFCondition cond; ++ + /** If Study already exists + */ + +@@ -2583,10 +2589,10 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec + + RequiredSize = imageSize - + ( handle_ -> maxBytesPerStudy - pStudyDesc[s]. StudySize ) ; +- deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ; ++ cond = deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ; ++ if (cond.bad()) return cond; + } + +- + } + else { + #ifdef DEBUG diff --git a/debian/patches/series b/debian/patches/series index 910203c1..e8951c70 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -5,3 +5,4 @@ remove_version.patch skip-bigendian-roundtrip-failure.patch hurd.patch CVE-2026-5663.patch +CVE-2026-10194.patch