CVE-2026-10194
authorDebian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)
committerÉtienne Mollier <emollier@debian.org>
Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)
commit 0f78a4ef6f645ea5530166e445e5436a5de58e75
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Mon May 4 17:48:30 2026 +0200

    Fixed remote heap buffer overflow in dcmqrscp.

    Thanks to 'elp3pinill0' for the bug report, detailed
    analysis, proof of concept and proposed fix.

    This closes DCMTK issue #1206.

Gbp-Pq: Name 0018-CVE-2026-10194.patch

dcmqrdb/libsrc/dcmqrdbi.cc

index 42467467f13654bd92810f4d2b3a7ed4d53760a6..6fd9d6b20cdf7d0b616a4c5361bb7ae8756bb758 100644 (file)
@@ -1,6 +1,6 @@
 /*
  *
- *  Copyright (C) 1993-2024, OFFIS e.V.
+ *  Copyright (C) 1993-2026, OFFIS e.V.
  *  All rights reserved.  See COPYRIGHT file for details.
  *
  *  This software and supporting documentation were developed by
@@ -2475,12 +2475,16 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages(StudyDescRec
 
     DB_IdxInitLoop (&(handle_ -> idxCounter)) ;
     while ( DB_IdxGetNext(&(handle_ -> idxCounter), &idxRec) == EC_Normal ) {
-    if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) {
-
-        StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ;
-        StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ;
-        StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ;
-    }
+        if ( ! ( strncmp(idxRec. StudyInstanceUID, StudyUID, n) ) ) {
+            StudyArray[nbimages]. idxCounter = handle_ -> idxCounter ;
+            StudyArray[nbimages]. RecordedDate = idxRec. RecordedDate ;
+            StudyArray[nbimages++]. ImageSize = idxRec. ImageSize ;
+            if (nbimages == MAX_NUMBER_OF_IMAGES) {
+                // too many images in this study, bail out
+                DCMQRDB_ERROR("maximum number of images per study (" << MAX_NUMBER_OF_IMAGES << ") exceeded");
+                return QR_EC_IndexDatabaseError;
+            }
+        }
     }
 
     /** Sort the StudyArray in order to have the oldest images first
@@ -2567,6 +2571,8 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec
     s = matchStudyUIDInStudyDesc (pStudyDesc, StudyUID,
                      (int)(handle_ -> maxStudiesAllowed)) ;
 
+    OFCondition cond;
+
     /** If Study already exists
      */
 
@@ -2587,10 +2593,10 @@ OFCondition DcmQueryRetrieveIndexDatabaseHandle::checkupinStudyDesc(StudyDescRec
 
         RequiredSize = imageSize -
             ( handle_ -> maxBytesPerStudy - pStudyDesc[s]. StudySize ) ;
-        deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ;
+        cond = deleteOldestImages(pStudyDesc, s, StudyUID, RequiredSize) ;
+        if (cond.bad()) return cond;
     }
 
-
     }
     else {
 #ifdef DEBUG