From: Debian Med Packaging Team Date: Tue, 7 Jul 2026 20:38:06 +0000 (+0200) Subject: CVE-2026-10194 X-Git-Tag: archive/raspbian/3.6.9-5+rpi1+deb13u3^2~8 X-Git-Url: https://dgit.raspbian.org/%22http://www.example.com/cgi/%22/%22http:/www.example.com/cgi/%22?a=commitdiff_plain;h=698ea94865694dff86f2da560acb412e3c2a542f;p=dcmtk.git CVE-2026-10194 commit 0f78a4ef6f645ea5530166e445e5436a5de58e75 Author: Marco Eichelberg Date: Mon May 4 17:48:30 2026 +0200 Fixed remote heap buffer overflow in dcmqrscp. Thanks to 'elp3pinill0' for the bug report, detailed analysis, proof of concept and proposed fix. This closes DCMTK issue #1206. Gbp-Pq: Name 0018-CVE-2026-10194.patch --- diff --git a/dcmqrdb/libsrc/dcmqrdbi.cc b/dcmqrdb/libsrc/dcmqrdbi.cc index 42467467..6fd9d6b2 100644 --- a/dcmqrdb/libsrc/dcmqrdbi.cc +++ b/dcmqrdb/libsrc/dcmqrdbi.cc @@ -1,6 +1,6 @@ /* * - * Copyright (C) 1993-2024, OFFIS e.V. + * Copyright (C) 1993-2026, OFFIS e.V. * All rights reserved. See COPYRIGHT file for details. * * This software and supporting documentation were developed by @@ -2475,12 +2475,16 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages(StudyDescRec DB_IdxInitLoop (&(handle_ -> idxCounter)) ; while ( DB_IdxGetNext(&(handle_ -> idxCounter), &idxRec) == EC_Normal ) { - if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) { - - StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ; - StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ; - StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ; - } + if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) { + StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ; + StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ; + StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ; + if (nbimages == MAX_NUMBER_OF_IMAGES) { + // too many images in this study, bail out + DCMQRDB_ERROR("maximum number of images per study (" << MAX_NUMBER_OF_IMAGES << ") exceeded"); + return QR_EC_IndexDatabaseError; + } + } } /** Sort the StudyArray in order to have the oldest images first @@ -2567,6 +2571,8 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec s = matchStudyUIDInStudyDesc (pStudyDesc, StudyUID, (int)(handle_ -> maxStudiesAllowed)) ; + OFCondition cond; + /** If Study already exists */ @@ -2587,10 +2593,10 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec RequiredSize = imageSize - ( handle_ -> maxBytesPerStudy - pStudyDesc[s]. StudySize ) ; - deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ; + cond = deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ; + if (cond.bad()) return cond; } - } else { #ifdef DEBUG