DEBIAN-CVE-2026-5437

Source
https://security-tracker.debian.org/tracker/CVE-2026-5437
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5437.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-5437
Upstream
  • CVE-2026-5437
Published
2026-04-09T15:16:15.093Z
Modified
2026-06-11T09:04:21.812471507Z
Summary
[none]
Details

An out-of-bounds read vulnerability exists in DicomStreamReader during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocated metadata buffer. Although this issue does not typically crash the server or expose data directly to the attacker, it reflects insufficient input validation in the parsing logic.

References

Affected packages

Debian:11 / orthanc

Package

Name
orthanc
Purl
pkg:deb/debian/orthanc?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.9.2+really1.9.1+dfsg-1
1.9.2+really1.9.1+dfsg-1+deb11u1
1.9.2+really1.9.1+dfsg-1+deb11u2
1.9.3+dfsg-1
1.9.5+dfsg-1
1.9.6+dfsg-1
1.9.7+dfsg-1
1.9.7+dfsg-2
1.9.7+dfsg-3
1.9.7+dfsg-4
1.9.7+dfsg-5
1.9.7+dfsg-6
1.10.0+dfsg-1
1.10.1+dfsg-1
1.10.1+dfsg-2
1.12.1+dfsg-1
1.12.1+dfsg-2
1.12.1+dfsg-3
1.12.1+dfsg-4
1.12.2+dfsg-1
1.12.3+dfsg-1
1.12.3+dfsg-2
1.12.4+dfsg-1
1.12.4+dfsg-2
1.12.4+dfsg-3
1.12.4+dfsg-4
1.12.5+dfsg-1
1.12.5+dfsg-2
1.12.6+dfsg-1
1.12.7+dfsg-1
1.12.7+dfsg-2
1.12.7+dfsg-3
1.12.7+dfsg-4
1.12.9+dfsg-1
1.12.9+dfsg-2
1.12.10+dfsg-1
1.12.10+dfsg-2
1.12.10+dfsg-3
1.12.10+dfsg-4
1.12.10+dfsg-5
1.12.11+dfsg-1
1.12.11+dfsg-2
1.12.11+dfsg-3
1.12.11+dfsg-4
1.12.11+dfsg-5
1.12.11+dfsg-6
1.12.11+dfsg-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5437.json"

Debian:12 / orthanc

Package

Name
orthanc
Purl
pkg:deb/debian/orthanc?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.10.1+dfsg-2
1.10.1+dfsg-2+deb12u1
1.12.1+dfsg-1
1.12.1+dfsg-2
1.12.1+dfsg-3
1.12.1+dfsg-4
1.12.2+dfsg-1
1.12.3+dfsg-1
1.12.3+dfsg-2
1.12.4+dfsg-1
1.12.4+dfsg-2
1.12.4+dfsg-3
1.12.4+dfsg-4
1.12.5+dfsg-1
1.12.5+dfsg-2
1.12.6+dfsg-1
1.12.7+dfsg-1
1.12.7+dfsg-2
1.12.7+dfsg-3
1.12.7+dfsg-4
1.12.9+dfsg-1
1.12.9+dfsg-2
1.12.10+dfsg-1
1.12.10+dfsg-2
1.12.10+dfsg-3
1.12.10+dfsg-4
1.12.10+dfsg-5
1.12.11+dfsg-1
1.12.11+dfsg-2
1.12.11+dfsg-3
1.12.11+dfsg-4
1.12.11+dfsg-5
1.12.11+dfsg-6
1.12.11+dfsg-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5437.json"

Debian:13 / orthanc

Package

Name
orthanc
Purl
pkg:deb/debian/orthanc?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.12.7+dfsg-4
1.12.9+dfsg-1
1.12.9+dfsg-2
1.12.10+dfsg-1
1.12.10+dfsg-2
1.12.10+dfsg-3
1.12.10+dfsg-4
1.12.10+dfsg-5
1.12.11+dfsg-1
1.12.11+dfsg-2
1.12.11+dfsg-3
1.12.11+dfsg-4
1.12.11+dfsg-5
1.12.11+dfsg-6
1.12.11+dfsg-7

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5437.json"

Debian:14 / orthanc

Package

Name
orthanc
Purl
pkg:deb/debian/orthanc?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.10+dfsg-4

Affected versions

1.*
1.12.7+dfsg-4
1.12.9+dfsg-1
1.12.9+dfsg-2
1.12.10+dfsg-1
1.12.10+dfsg-2
1.12.10+dfsg-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5437.json"