DEBIAN-CVE-2026-44035

Source
https://security-tracker.debian.org/tracker/CVE-2026-44035
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44035.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-44035
Upstream
Published
2026-10-08T13:17:17Z
Modified
2026-10-09T11:00:08Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. Any application that opens the DICOMDIR is affected, including dcmgpdir and media viewers built on DCMTK. The issue is fixed in commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f.

References

Affected packages

Debian:12 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.7-8
3.6.7-9~deb12u1
3.6.7-9~deb12u2
3.6.7-9~deb12u3
3.6.7-9~deb12u4
3.6.7-9
3.6.7-9.1
3.6.7-11
3.6.7-12
3.6.7-13
3.6.7-14
3.6.7-15
3.6.8~git20221024.b8950f9-1
3.6.8~git20221024.b8950f9-2
3.6.8~git20221024.b8950f9-3
3.6.8~git20231027.1549d8c-1
3.6.8~git20231027.1549d8c-2
3.6.8-1
3.6.8-2
3.6.8-3
3.6.8-4
3.6.8-5
3.6.8-6
3.6.8-7
3.6.9-1
3.6.9-2
3.6.9-3
3.6.9-4
3.6.9-5
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44035.json"

Debian:13 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.9-5
3.6.9-5+deb13u1
3.6.9-5+deb13u2
3.6.9-5+deb13u3
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44035.json"

Debian:14 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.9-5
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44035.json"