Hello,
The "dcmtk" package must be fixed by introducing the following upstream patch:
https://github.com/DCMTK/dcmtk/commit/885ff0f10372bd589b5f44cea974f28a3964cb0f
[...]
I believe the appropriate course of action is to wait for dcmtk
3.7.1 and properly transition once it is out. In the meantime,
I am preparing a dcmtk upload to unstable reverting that patch.
As a quick followup, Orthanc 1.13.0 is now released. Static builds of
Orthanc bundle the fix for CVE-2026-10528 [1].
The orthanc Debian package has been updated for this new upstream
release and "orthanc/1.13.0+dfsg-1" is currently waiting for a sponsored
upload [2].
However, even after "orthanc/1.13.0+dfsg-1" is uploaded, CVE-2026-10528
will not be fixed until the dcmtk package is updated with the patch
referenced in the previous messages in this thread, as the orthanc
package dynamically links against dcmtk.
Regards,
Sébastien-
[1] https://orthanc.uclouvain.be/hg/orthanc/file/Orthanc-1.13.0/NEWS
[2] https://lists.debian.org/debian-med/2026/08/msg00023.html