Back Linuxsecurity Debian 11: DLA-4443-1 DCMTK Important MemCorruption SegFault CVE-2025
CVE-2025-14607 Possible memory corruption caused by illegal attributes in datasets which are processed by DcmByteString functions. CVE-2025-14841 Invalid messages sent to dcmqrscp, the Image Central Test Node, may trigger a segmentation fault due to a NULL pointer being de-referenced. For Debian 11 bullseye, these problems have been fixed in version 3.6.5-1+deb11u6. We recommend that you upgrade your dcmtk packages. For the detailed security status of dcmtk please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
CVE-2025-14607 Possible memory corruption caused by illegal attributes in datasets which are processed by DcmByteString functions. CVE-2025-14841 Invalid messages sent to dcmqrscp, the Image Central Test Node, may trigger a segmentation fault due to a NULL pointer being de-referenced. For Debian 11 bullseye, these problems have been fixed in version 3.6.5-1+deb11u6. We recommend that you upgrade your dcmtk packages. For the detailed security status of dcmtk please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
