CVE-2026-10194: OFFIS DCMTK dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflow
A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. This patch is called 0f78a4ef6f645ea5530166e445e5436a5de58e75. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OFFIS DCMTK 3.7.0to a version that resolves this vulnerability.Patch 0f78a4ef6f645ea5530166e445e5436a5de58e75
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10194?
The severity of CVE-2026-10194 is medium, with a score of 6.3.
What is the risk associated with CVE-2026-10194?
CVE-2026-10194 has a risk rating of 46, indicating a significant vulnerability.
How do I fix CVE-2026-10194?
To fix CVE-2026-10194, update to the latest version of OFFIS DCMTK that addresses this vulnerability.
What components are affected by CVE-2026-10194?
CVE-2026-10194 affects the dcmqrscp component of OFFIS DCMTK version 3.7.0.
What type of vulnerability is CVE-2026-10194?
CVE-2026-10194 is classified as a heap-based buffer overflow.