Bug 34946 - dcmtk new security issues CVE-2025-14607 and CVE-2025-14841
Summary: dcmtk new security issues CVE-2025-14607 and CVE-2025-14841
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-01-07 15:42 CET by Nicolas Salguero
Modified: 2026-02-16 17:37 CET (History)
4 users (show)

See Also:
Source RPM: dcmtk-3.6.7-4.6.mga9.src.rpm
CVE: CVE-2025-14607, CVE-2025-14841
Status comment:


Attachments

Description Nicolas Salguero 2026-01-07 15:42:05 CET
openSUSE has issued an advisory on January 6:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/WA2BG2LFPVCYESQA5KLHS3YDK74NTELX/
Nicolas Salguero 2026-01-07 15:42:47 CET

Status comment: (none) => Fixed upstream in 3.7.0
CVE: (none) => CVE-2025-14607, CVE-2025-14841
Source RPM: (none) => dcmtk-3.6.7-4.6.mga9.src.rpm

Comment 1 Nicolas Salguero 2026-01-08 16:38:04 CET
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

OFFIS DCMTK dcmdata dcbytstr.cc makeDicomByteString memory corruption. (CVE-2025-14607)

OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference. (CVE-2025-14841)

References:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/WA2BG2LFPVCYESQA5KLHS3YDK74NTELX/
========================

Updated packages in core/updates_testing:
========================
dcmtk-3.6.7-4.7.mga9
lib(64)dcmtk17-3.6.7-4.7.mga9
lib(64)dcmtk-devel-3.6.7-4.7.mga9

from SRPM:
dcmtk-3.6.7-4.7.mga9.src.rpm

Status comment: Fixed upstream in 3.7.0 => (none)
Status: NEW => ASSIGNED
Assignee: bugsquad => qa-bugs

katnatek 2026-01-09 01:51:23 CET

Keywords: (none) => advisory

Comment 2 Herman Viaene 2026-01-09 11:44:03 CET
MGA9-64 server Plasma Wayland on Compaq H000SB
No installation issues
Ref bug 33930
Using olive-editor to import an .mpg, mp4 and an .avi file and use these in the Sequence Viewer.
The avi file has no sound, video in itself is OK. Both mpg and mp4 files (essentially the same video) have the same problem: the sound starts OK but lags behind very quickly.
I don't know what to think of it. This laptop is certainly underpowered for video editing, but the files play OK in vlc on the same laptop, and I didn't notice that effect on the previous update bug 34718.

CC: (none) => herman.viaene

Comment 3 Len Lawrence 2026-02-13 18:51:31 CET
Mageia9 x86_64

Checked that the dcmtk packages were all in place and ran a few tests successfully.  Updated via qarepo and repeated the tests.
$ dcmtls_tests
[...]
2026-02-13 16:34:30.182 DEBUG: DcmBaseSCPPool: Worker thread #139939127736000 returns with code: Normal
2026-02-13 16:34:30.182 DEBUG: DcmBaseSCPPool: Worker thread #139939127736000 exited with error: Normal
2026-02-13 16:34:30.182 DEBUG: Cleaning up internal association and network structures
Test results for module 'dcmtls': 2 succeeded, 0 failed
$ dcmnet_tests 
Test results for module 'dcmnet': 2 succeeded, 0 failed.
$ dcmrt_tests
Test results for module 'dcmrt': 2 succeeded, 0 failed.
$ dcmiod_tests
Test results for module 'dcmiod': 3 succeeded, 0 failed.
$ dcmsr_tests
Test results for module 'dcmsr': 82 succeeded, 0 failed.

No change there so this looks good.

CC: (none) => tarazed25

Comment 4 Len Lawrence 2026-02-13 18:53:51 CET
There are command-line tools like:
dcmdump
dcmmodify
storescp
storescu

but testing these is out of my league.
Comment 5 katnatek 2026-02-14 18:54:31 CET
Thanks gentlemen

Whiteboard: (none) => MGA9-64-OK

Comment 6 Thomas Andrews 2026-02-16 01:50:20 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 7 Mageia Robot 2026-02-16 17:37:39 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0040.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.