From e9679a22dafe90d2fe0e3e2dfba01d6db9427d80 Mon Sep 17 00:00:00 2001 From: Debian Med Packaging Team Date: Tue, 23 Jun 2026 21:44:21 +0200 Subject: [PATCH] CVE-2026-10194 commit 0f78a4ef6f645ea5530166e445e5436a5de58e75 Author: Marco Eichelberg Date: Mon May 4 17:48:30 2026 +0200 Fixed remote heap buffer overflow in dcmqrscp. Thanks to 'elp3pinill0' for the bug report, detailed analysis, proof of concept and proposed fix. This closes DCMTK issue #1206. Gbp-Pq: Name 0018-CVE-2026-10194.patch --- dcmqrdb/libsrc/dcmqrdbi.cc | 24 +++++++++++++++--------- 1 file changed, 15 insertions(+), 9 deletions(-) diff --git a/dcmqrdb/libsrc/dcmqrdbi.cc b/dcmqrdb/libsrc/dcmqrdbi.cc index 42467467..6fd9d6b2 100644 --- a/dcmqrdb/libsrc/dcmqrdbi.cc +++ b/dcmqrdb/libsrc/dcmqrdbi.cc @@ -1,6 +1,6 @@ /* * - * Copyright (C) 1993-2024, OFFIS e.V. + * Copyright (C) 1993-2026, OFFIS e.V. * All rights reserved. See COPYRIGHT file for details. * * This software and supporting documentation were developed by @@ -2475,12 +2475,16 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages(StudyDescRec DB_IdxInitLoop (&(handle_ -> idxCounter)) ; while ( DB_IdxGetNext(&(handle_ -> idxCounter), &idxRec) == EC_Normal ) { - if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) { - - StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ; - StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ; - StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ; - } + if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) { + StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ; + StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ; + StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ; + if (nbimages == MAX_NUMBER_OF_IMAGES) { + // too many images in this study, bail out + DCMQRDB_ERROR("maximum number of images per study (" << MAX_NUMBER_OF_IMAGES << ") exceeded"); + return QR_EC_IndexDatabaseError; + } + } } /** Sort the StudyArray in order to have the oldest images first @@ -2567,6 +2571,8 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec s = matchStudyUIDInStudyDesc (pStudyDesc, StudyUID, (int)(handle_ -> maxStudiesAllowed)) ; + OFCondition cond; + /** If Study already exists */ @@ -2587,10 +2593,10 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec RequiredSize = imageSize - ( handle_ -> maxBytesPerStudy - pStudyDesc[s]. StudySize ) ; - deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ; + cond = deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ; + if (cond.bad()) return cond; } - } else { #ifdef DEBUG -- 2.30.2