Fixed path traversal in DcmSCU bit-pres. C-GET.
authorMichael Onken <onken@open-connections.de>
Mon, 6 Jul 2026 20:39:03 +0000 (22:39 +0200)
committerÉtienne Mollier <emollier@debian.org>
Mon, 6 Jul 2026 20:39:03 +0000 (22:39 +0200)
commit3a628dc6dde08c82badcedc6cf889276711afd39
tree91747d9e27cd0004621a390e500ece8afe4ee975
parent94e5f626d93e99e57125767fa2556907e703b95b
Fixed path traversal in DcmSCU bit-pres. C-GET.

Applied-Upstream: eca9a03dda7d4fc1faa7e5a6dac9617938cf5803
Last-Update: 2026-05-12
Reviewed-By: Étienne Mollier <emollier@debian.org>
Bug-Debian: https://bugs.debian.org/1141411

In DCMSCU_STORAGE_BIT_PRESERVING mode, the C-STORE sub-operation
handler in handleCGETSession() built the on-disk filename from the
peer-supplied AffectedSOPInstanceUID without sanitization, allowing
a malicious C-STORE SCP to write files outside the configured
storage directory via path-separator or "../" sequences in the UID.

The DISK mode path was already sanitized (via createStorageFilename(),
fixed in commit f06a86751 for CVE-2022-2120); this branch was missed.
The fix mirrors the same pattern (sanitize a local OFString copy) so
the request struct stays intact and the C-STORE response still echoes
the peer's original UID per protocol.

Affects all consumers of DcmSCU using DCMSCU_STORAGE_BIT_PRESERVING,
including getscu --bit-preserving.

This fixes DCMTK issue #1207.

Thanks to Abhinav Agarwal for the report and analysis.

Gbp-Pq: Name CVE-2026-50003.patch
dcmnet/libsrc/scu.cc