Hello,

The "dcmtk" package must be fixed by introducing the following upstream patch:
https://github.com/DCMTK/dcmtk/commit/885ff0f10372bd589b5f44cea974f28a3964cb0f
[...]
I believe the appropriate course of action is to wait for dcmtk
3.7.1 and properly transition once it is out.  In the meantime,
I am preparing a dcmtk upload to unstable reverting that patch.

As a quick followup, Orthanc 1.13.0 is now released. Static builds of Orthanc bundle the fix for CVE-2026-10528 [1].

The orthanc Debian package has been updated for this new upstream release and "orthanc/1.13.0+dfsg-1" is currently waiting for a sponsored upload [2].

However, even after "orthanc/1.13.0+dfsg-1" is uploaded, CVE-2026-10528 will not be fixed until the dcmtk package is updated with the patch referenced in the previous messages in this thread, as the orthanc package dynamically links against dcmtk.

Regards,
Sébastien-

[1] https://orthanc.uclouvain.be/hg/orthanc/file/Orthanc-1.13.0/NEWS
[2] https://lists.debian.org/debian-med/2026/08/msg00023.html

Reply via email to