From adfd5a020cb585717f7c10a724b920a74f8d0570 Mon Sep 17 00:00:00 2001 From: =?utf8?q?=C3=89tienne=20Mollier?= Date: Tue, 23 Jun 2026 21:42:21 +0200 Subject: [PATCH] CVE-2026-12805.patch: new: fix CVE-2026-12805. This patch fixes a risk of buffer overflow by ensuring negative error codes in XMLNode::parseFile are properly handled, as well a NULL values. Closes: #1140562 --- debian/patches/0019-CVE-2026-12805.patch | 34 ++++++++++++++++++++++++ debian/patches/series | 1 + 2 files changed, 35 insertions(+) create mode 100644 debian/patches/0019-CVE-2026-12805.patch diff --git a/debian/patches/0019-CVE-2026-12805.patch b/debian/patches/0019-CVE-2026-12805.patch new file mode 100644 index 00000000..2cf189f3 --- /dev/null +++ b/debian/patches/0019-CVE-2026-12805.patch @@ -0,0 +1,34 @@ +commit 1d4b3815c0987840a983160bfc671fef63a3105b +Author: Marco Eichelberg +Date: Sat May 23 17:07:58 2026 +0200 + + Fixed buffer overflow in XMLNode::parseFile(). + + Fixed a heap buffer overflow that could occur in the XML parser + when reading from a named pipe. + + Thanks to Cristhian Daniel Rivas Zúñiga and Sebastian Andres Muñoz Morera + (Insituto Tecnológico de Costa Rica) for the bug report and fix. + + This closes DCMTK issue #1208. + +--- dcmtk.orig/ofstd/libsrc/ofxml.cc ++++ dcmtk/ofstd/libsrc/ofxml.cc +@@ -1,6 +1,6 @@ + /* + * +- * Copyright (C) 2011-2023, OFFIS e.V. ++ * Copyright (C) 2011-2026, OFFIS e.V. + * All rights reserved. See COPYRIGHT file for details. + * + * This software and supporting documentation were slightly modified by +@@ -1961,7 +1961,8 @@ + if (f==NULL) { if (pResults) pResults->error=eXMLErrorFileNotFound; return emptyXMLNode; } + fseek(f,0,SEEK_END); + int l=OFstatic_cast(int, ftell(f)),headerSz=0; +- if (!l) { if (pResults) pResults->error=eXMLErrorEmpty; fclose(f); return emptyXMLNode; } ++ // DCMTK: handle situation where ftell() returns -1 ++ if (l <= 0) { if (pResults) pResults->error=eXMLErrorEmpty; fclose(f); return emptyXMLNode; } + fseek(f,0,SEEK_SET); + unsigned char *buf=OFreinterpret_cast(unsigned char*, malloc(l+4)); + l=OFstatic_cast(int, fread(buf,1,l,f)); diff --git a/debian/patches/series b/debian/patches/series index 7313c56b..257af226 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -14,3 +14,4 @@ remove_version.patch 0016-CVE-2026-5663.patch 0017-CVE-2025-14841.patch 0018-CVE-2026-10194.patch +0019-CVE-2026-12805.patch -- 2.30.2