DEBIAN-CVE-2026-44031

Source
https://security-tracker.debian.org/tracker/CVE-2026-44031
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44031.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-44031
Upstream
Published
2026-10-08T13:17:17Z
Modified
2026-10-09T11:00:08Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exhaustion and process crash) via a DICOM dataset containing deeply nested sequences (SQ elements). The dataset can be sent in a C-STORE request to storescp, dcmrecv, dcmqrscp, or any other DICOM service built on DCMTK, because the received dataset is parsed before any authentication takes place. Local tools such as dcmdump also crash when opening such a file. The issue is fixed in commit 885ff0f10372bd589b5f44cea974f28a3964cb0f, which adds a configurable sequence nesting depth limit (default 64).

References

Affected packages

Debian:12 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.7-8
3.6.7-9~deb12u1
3.6.7-9~deb12u2
3.6.7-9~deb12u3
3.6.7-9~deb12u4
3.6.7-9
3.6.7-9.1
3.6.7-11
3.6.7-12
3.6.7-13
3.6.7-14
3.6.7-15
3.6.8~git20221024.b8950f9-1
3.6.8~git20221024.b8950f9-2
3.6.8~git20221024.b8950f9-3
3.6.8~git20231027.1549d8c-1
3.6.8~git20231027.1549d8c-2
3.6.8-1
3.6.8-2
3.6.8-3
3.6.8-4
3.6.8-5
3.6.8-6
3.6.8-7
3.6.9-1
3.6.9-2
3.6.9-3
3.6.9-4
3.6.9-5
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44031.json"

Debian:13 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.9-5
3.6.9-5+deb13u1
3.6.9-5+deb13u2
3.6.9-5+deb13u3
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44031.json"

Debian:14 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.9-5
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44031.json"