CVE-2026-10194.patch: new: fix CVE-2026-10194.
authorÉtienne Mollier <emollier@debian.org>
Mon, 8 Jun 2026 17:13:13 +0000 (19:13 +0200)
committerÉtienne Mollier <emollier@debian.org>
Mon, 8 Jun 2026 17:13:13 +0000 (19:13 +0200)
Closes: #1139181
debian/patches/CVE-2026-10194.patch [new file with mode: 0644]
debian/patches/series

diff --git a/debian/patches/CVE-2026-10194.patch b/debian/patches/CVE-2026-10194.patch
new file mode 100644 (file)
index 0000000..7dbe7f9
--- /dev/null
@@ -0,0 +1,67 @@
+Description: Fixed remote heap buffer overflow in dcmqrscp.
+ Thanks to 'elp3pinill0' for the bug report, detailed
+ analysis, proof of concept and proposed fix.
+Author: Marco Eichelberg <eichelberg@offis.de>
+Applied-Upstream: 0f78a4ef6f645ea5530166e445e5436a5de58e75
+Last-Update: 2026-05-04
+Bug: https://support.dcmtk.org/redmine/issues/1206
+Bug-Debian: https://bugs.debian.org/1139181
+Reviewed-By: Étienne Mollier <emollier@debian.org>
+
+diff --git a/dcmqrdb/libsrc/dcmqrdbi.cc b/dcmqrdb/libsrc/dcmqrdbi.cc
+index c91116a1c..ee308abe1 100644
+--- a/dcmqrdb/libsrc/dcmqrdbi.cc
++++ b/dcmqrdb/libsrc/dcmqrdbi.cc
+@@ -1,6 +1,6 @@
+ /*
+  *
+- *  Copyright (C) 1993-2025, OFFIS e.V.
++ *  Copyright (C) 1993-2026, OFFIS e.V.
+  *  All rights reserved.  See COPYRIGHT file for details.
+  *
+  *  This software and supporting documentation were developed by
+@@ -2471,12 +2471,16 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages(StudyDescRec
+     DB_IdxInitLoop (&(handle_ -> idxCounter)) ;
+     while ( DB_IdxGetNext(&(handle_ -> idxCounter), &idxRec) == EC_Normal ) {
+-    if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) {
+-
+-        StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ;
+-        StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ;
+-        StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ;
+-    }
++        if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) {
++            StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ;
++            StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ;
++            StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ;
++            if (nbimages == MAX_NUMBER_OF_IMAGES) {
++                // too many images in this study, bail out
++                DCMQRDB_ERROR("maximum number of images per study (" << MAX_NUMBER_OF_IMAGES << ") exceeded");
++                return QR_EC_IndexDatabaseError;
++            }
++        }
+     }
+     /** Sort the StudyArray in order to have the oldest images first
+@@ -2563,6 +2567,8 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec
+     s = matchStudyUIDInStudyDesc (pStudyDesc, StudyUID,
+                      (int)(handle_ -> maxStudiesAllowed)) ;
++    OFCondition cond;
++
+     /** If Study already exists
+      */
+@@ -2583,10 +2589,10 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec
+         RequiredSize = imageSize -
+             ( handle_ -> maxBytesPerStudy - pStudyDesc[s]. StudySize ) ;
+-        deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ;
++        cond = deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ;
++        if (cond.bad()) return cond;
+     }
+-
+     }
+     else {
+ #ifdef DEBUG
index 910203c110d1e0c09446840f3a3caa4a6f0b4e94..e8951c704c5e6f502f2c36bbe5357763df509cef 100644 (file)
@@ -5,3 +5,4 @@ remove_version.patch
 skip-bigendian-roundtrip-failure.patch
 hurd.patch
 CVE-2026-5663.patch
+CVE-2026-10194.patch