Fixed remote heap buffer overflow in dcmqrscp.
authorMarco Eichelberg <eichelberg@offis.de>
Mon, 8 Jun 2026 17:14:40 +0000 (19:14 +0200)
committerÉtienne Mollier <emollier@debian.org>
Mon, 8 Jun 2026 17:14:40 +0000 (19:14 +0200)
Applied-Upstream: 0f78a4ef6f645ea5530166e445e5436a5de58e75
Last-Update: 2026-05-04
Bug: https://support.dcmtk.org/redmine/issues/1206
Bug-Debian: https://bugs.debian.org/1139181
Reviewed-By: Étienne Mollier <emollier@debian.org>
Thanks to 'elp3pinill0' for the bug report, detailed
analysis, proof of concept and proposed fix.

Gbp-Pq: Name CVE-2026-10194.patch

dcmqrdb/libsrc/dcmqrdbi.cc

index c91116a1c5171400a4dd3efe20e22a17eaec4131..ee308abe15ef1b7b3ef19da04c4cb30b83b562af 100644 (file)
@@ -1,6 +1,6 @@
 /*
  *
- *  Copyright (C) 1993-2025, OFFIS e.V.
+ *  Copyright (C) 1993-2026, OFFIS e.V.
  *  All rights reserved.  See COPYRIGHT file for details.
  *
  *  This software and supporting documentation were developed by
@@ -2471,12 +2471,16 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages(StudyDescRec
 
     DB_IdxInitLoop (&(handle_ -> idxCounter)) ;
     while ( DB_IdxGetNext(&(handle_ -> idxCounter), &idxRec) == EC_Normal ) {
-    if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) {
-
-        StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ;
-        StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ;
-        StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ;
-    }
+        if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) {
+            StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ;
+            StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ;
+            StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ;
+            if (nbimages == MAX_NUMBER_OF_IMAGES) {
+                // too many images in this study, bail out
+                DCMQRDB_ERROR("maximum number of images per study (" << MAX_NUMBER_OF_IMAGES << ") exceeded");
+                return QR_EC_IndexDatabaseError;
+            }
+        }
     }
 
     /** Sort the StudyArray in order to have the oldest images first
@@ -2563,6 +2567,8 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec
     s = matchStudyUIDInStudyDesc (pStudyDesc, StudyUID,
                      (int)(handle_ -> maxStudiesAllowed)) ;
 
+    OFCondition cond;
+
     /** If Study already exists
      */
 
@@ -2583,10 +2589,10 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec
 
         RequiredSize = imageSize -
             ( handle_ -> maxBytesPerStudy - pStudyDesc[s]. StudySize ) ;
-        deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ;
+        cond = deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ;
+        if (cond.bad()) return cond;
     }
 
-
     }
     else {
 #ifdef DEBUG