--- /dev/null
+commit 4c0e5c10079392c594d6a7abd95dd78ac0aa556a
+Author: Marco Eichelberg <eichelberg@offis.de>
+Date: Tue Dec 2 09:06:30 2025 +0100
+
+ Fixed bug in handling of odd-length data elements.
+
+ When a dataset containing an illegal odd-length attribute with a text VR
+ was read from file or received over a network connection, then accessing
+ the value of that attribute with DcmElement::getString() may return a
+ pointer to a string that was not properly null terminated. Using C string
+ functions such as strlen() or strcpy() on that string then lead to a read
+ beyond the end of a string, causing a segmentation fault.
+
+ Thanks to Zou Dikai <zoudikai@outlook.com> for the bug report and POC.
+
+ This closes DCMTK issue #1184.
+
+--- dcmtk.orig/dcmdata/libsrc/dcbytstr.cc
++++ dcmtk/dcmdata/libsrc/dcbytstr.cc
+@@ -658,7 +658,11 @@
+
+ /* terminate string after real length */
+ if (value != NULL)
++ {
+ value[lengthField] = 0;
++ value[lengthField+1] = 0;
++ }
++
+ /* enforce old (pre DCMTK 3.5.2) behaviour? */
+ if (!dcmAcceptOddAttributeLength.get())
+ {