DEBIAN-CVE-2026-97059

Source
https://security-tracker.debian.org/tracker/CVE-2026-97059
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97059.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-97059
Upstream
Published
2026-09-24T14:18:21Z
Modified
2026-09-25T06:00:08Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS Calculator
Summary
[none]
Details

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declaring more frames than the buffer contains to trigger heap over-reads that crash the application or leak adjacent heap memory.

References

Affected packages

Debian:12 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.7-8
3.6.7-9~deb12u1
3.6.7-9~deb12u2
3.6.7-9~deb12u3
3.6.7-9~deb12u4
3.6.7-9
3.6.7-9.1
3.6.7-11
3.6.7-12
3.6.7-13
3.6.7-14
3.6.7-15
3.6.8~git20221024.b8950f9-1
3.6.8~git20221024.b8950f9-2
3.6.8~git20221024.b8950f9-3
3.6.8~git20231027.1549d8c-1
3.6.8~git20231027.1549d8c-2
3.6.8-1
3.6.8-2
3.6.8-3
3.6.8-4
3.6.8-5
3.6.8-6
3.6.8-7
3.6.9-1
3.6.9-2
3.6.9-3
3.6.9-4
3.6.9-5
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97059.json"

Debian:13 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.9-5
3.6.9-5+deb13u1
3.6.9-5+deb13u2
3.6.9-5+deb13u3
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97059.json"

Debian:14 / dcmtk

Package

Name
dcmtk
Purl
pkg:deb/debian/dcmtk?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.6.9-5
3.6.9-6
3.7.0-1
3.7.0+really3.6.9-1
3.7.0+really3.7.0-0+exp1
3.7.0+really3.7.0-1
3.7.0+really3.7.0-2
3.7.0+really3.7.0-3
3.7.0+really3.7.0-4
3.7.0+really3.7.0-5
3.7.0+really3.7.0-6
3.7.0+really3.7.0-7

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-97059.json"