Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian 11: DLA-4443-1 DCMTK Important MemCorruption SegFault CVE-2025-14607

debian lts
Calendar Grey January 19, 2026
Dist Debian Esm H88
Two vulnerabilities in DCMTK affect medical image processing; upgrades are necessary to mitigate security risks.
Two vulnerabilities have been addressed in DCMTK, a collection of libraries and applications implementing large parts of the DICOM standard for medical images

Summary

CVE-2025-14607

Possible memory corruption caused by illegal attributes in datasets which
are processed by DcmByteString functions.

CVE-2025-14841

Invalid messages sent to dcmqrscp, the Image Central Test Node, may
trigger a segmentation fault due to a NULL pointer being de-referenced.

For Debian 11 bullseye, these problems have been fixed in version
3.6.5-1+deb11u6.

We recommend that you upgrade your dcmtk packages.

For the detailed security status of dcmtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/dcmtk

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: dcmtk
Version: 3.6.5-1+deb11u6
CVE ID: CVE-2025-14607 CVE-2025-14841
Debian Bug: 1122926 1123584

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here