- dcmtk (3.6.9-5+rpi1) trixie-staging; urgency=medium
++dcmtk (3.6.9-5+rpi1+deb13u2) trixie-staging; urgency=medium
+
+ [changes brought forward from 3.6.7-13+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Wed, 19 Jun 2024 20:44:47 +0000]
+ * Disable stack clash protection, it causes assembler errors on raspbian.
+
- -- Raspbian forward porter <root@raspbian.org> Thu, 01 May 2025 02:35:22 +0000
++ -- Raspbian forward porter <root@raspbian.org> Tue, 21 Jul 2026 11:23:02 +0000
++
+ dcmtk (3.6.9-5+deb13u2) trixie; urgency=medium
+
+ * Team upload.
+ * CVE-2026-12805.patch: new: fix CVE-2026-12805.
+ This patch fixes a risk of buffer overflow by ensuring negative error
+ codes in XMLNode::parseFile are properly handled, as well a NULL
+ values. (Closes: #1140562)
+
+ -- Étienne Mollier <emollier@debian.org> Tue, 23 Jun 2026 21:44:21 +0200
+
+ dcmtk (3.6.9-5+deb13u1) trixie; urgency=medium
+
+ * Team upload
+ * d/patches/*-CVE-2025-9732.patch: new.
+ These changes pulled from dcmtk upstream address CVE-2025-9732.
+ (Closes: #1113993)
+ * 0015-CVE-2025-14607.patch: new: fix CVE-2025-14607. (Closes: #1122926)
+ * 0016-CVE-2026-5663.patch: new: fix CVE-2026-5663. (Closes: #1133001)
+ * 0017-CVE-2025-14841.patch: new: fix CVE-2025-14841. (Closes: #1123584)
+ * 0018-CVE-2026-10194.patch: new: fix CVE-2026-10194. (Closes: #1139181)
+
+ -- Étienne Mollier <emollier@debian.org> Thu, 11 Jun 2026 20:54:58 +0200
dcmtk (3.6.9-5) unstable; urgency=medium