--- /dev/null
+Description: Fixed remote heap buffer overflow in dcmqrscp.
+ Thanks to 'elp3pinill0' for the bug report, detailed
+ analysis, proof of concept and proposed fix.
+Author: Marco Eichelberg <eichelberg@offis.de>
+Applied-Upstream: 0f78a4ef6f645ea5530166e445e5436a5de58e75
+Last-Update: 2026-05-04
+Bug: https://support.dcmtk.org/redmine/issues/1206
+Bug-Debian: https://bugs.debian.org/1139181
+Reviewed-By: Étienne Mollier <emollier@debian.org>
+
+diff --git a/dcmqrdb/libsrc/dcmqrdbi.cc b/dcmqrdb/libsrc/dcmqrdbi.cc
+index c91116a1c..ee308abe1 100644
+--- a/dcmqrdb/libsrc/dcmqrdbi.cc
++++ b/dcmqrdb/libsrc/dcmqrdbi.cc
+@@ -1,6 +1,6 @@
+ /*
+ *
+- * Copyright (C) 1993-2025, OFFIS e.V.
++ * Copyright (C) 1993-2026, OFFIS e.V.
+ * All rights reserved. See COPYRIGHT file for details.
+ *
+ * This software and supporting documentation were developed by
+@@ -2471,12 +2471,16 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages(StudyDescRec
+
+ DB_IdxInitLoop (&(handle_ -> idxCounter)) ;
+ while ( DB_IdxGetNext(&(handle_ -> idxCounter), &idxRec) == EC_Normal ) {
+- if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) {
+-
+- StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ;
+- StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ;
+- StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ;
+- }
++ if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) {
++ StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ;
++ StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ;
++ StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ;
++ if (nbimages == MAX_NUMBER_OF_IMAGES) {
++ // too many images in this study, bail out
++ DCMQRDB_ERROR("maximum number of images per study (" << MAX_NUMBER_OF_IMAGES << ") exceeded");
++ return QR_EC_IndexDatabaseError;
++ }
++ }
+ }
+
+ /** Sort the StudyArray in order to have the oldest images first
+@@ -2563,6 +2567,8 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec
+ s = matchStudyUIDInStudyDesc (pStudyDesc, StudyUID,
+ (int)(handle_ -> maxStudiesAllowed)) ;
+
++ OFCondition cond;
++
+ /** If Study already exists
+ */
+
+@@ -2583,10 +2589,10 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec
+
+ RequiredSize = imageSize -
+ ( handle_ -> maxBytesPerStudy - pStudyDesc[s]. StudySize ) ;
+- deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ;
++ cond = deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ;
++ if (cond.bad()) return cond;
+ }
+
+-
+ }
+ else {
+ #ifdef DEBUG