# HG changeset patch # User Alain Mazy # Date 1772552244 -3600 # Node ID 983a74f5b8757519a7a43a3e61a037be994f58e6 # Parent f1140bd7ed6516e40916c98a0cdaa5613423c9ef Fix possible overflow when rows/columns DICOM tags exceed the maximum value for a US (65535) diff -r f1140bd7ed65 -r 983a74f5b875 NEWS --- a/NEWS Tue Mar 03 16:04:54 2026 +0100 +++ b/NEWS Tue Mar 03 16:37:24 2026 +0100 @@ -144,6 +144,7 @@ "TimeZoneOffsetFromUTC" is added to the "ExtraMainDicomTags" at Patient level. https://discourse.orthanc-server.org/t/jobs-api-the-dicommovescu-job-doesnt-seems-to-track-progress/3140/14 - Fix possible overflow when calling /tools/create-dicom with a PAM file. + - Fix possible overflow when rows/columns DICOM tags exceed the maximum value for a US (65535). * Upgraded dependencies for static builds: - civetweb 1.16, including patch for CVE-2025-55763 - SQLite 3.50.4 diff -r f1140bd7ed65 -r 983a74f5b875 OrthancFramework/Sources/DicomFormat/DicomImageInformation.cpp --- a/OrthancFramework/Sources/DicomFormat/DicomImageInformation.cpp Tue Mar 03 16:04:54 2026 +0100 +++ b/OrthancFramework/Sources/DicomFormat/DicomImageInformation.cpp Tue Mar 03 16:37:24 2026 +0100 @@ -42,6 +42,8 @@ #include #include +static const uint64_t MAX_FRAME_SIZE = 4ul * 1024ul * 1024ul * 1024ul; // defensive approach: set a reasonable max size for a frame + namespace Orthanc { DicomImageInformation::DicomImageInformation(const DicomMap& values) @@ -130,6 +132,11 @@ values.GetValue(DICOM_TAG_COLUMNS).ParseFirstUnsignedInteger(width_); // in some US images, we've seen tag values of "800\0"; that's why we parse the 'first' value values.GetValue(DICOM_TAG_ROWS).ParseFirstUnsignedInteger(height_); + if (height_ > 65535 || width_ > 65535) + { + throw OrthancException(ErrorCode_BadFileFormat, "Image width or height exceed DICOM VR US range (65535)"); + } + if (!values.ParseUnsignedInteger32(bitsAllocated_, DICOM_TAG_BITS_ALLOCATED)) { throw OrthancException(ErrorCode_BadFileFormat); @@ -470,10 +477,17 @@ } else { - return (GetHeight() * - GetWidth() * - GetBytesPerValue() * - GetChannelCount()); + uint64_t totalFrameSize = static_cast(GetHeight()) * + GetWidth() * + GetBytesPerValue() * + GetChannelCount(); + + if (totalFrameSize > MAX_FRAME_SIZE) + { + throw OrthancException(ErrorCode_BadFileFormat, "DICOM Frame size overflow"); + } + + return static_cast(totalFrameSize); } } diff -r f1140bd7ed65 -r 983a74f5b875 OrthancFramework/Sources/Images/PamReader.cpp --- a/OrthancFramework/Sources/Images/PamReader.cpp Tue Mar 03 16:04:54 2026 +0100 +++ b/OrthancFramework/Sources/Images/PamReader.cpp Tue Mar 03 16:37:24 2026 +0100 @@ -38,7 +38,7 @@ #include #include -static const uint64_t MAX_PAM_IMAGE_BUFFER_SIZE = 4ul * 1024ul * 1024ul * 1024ul; +static const uint64_t MAX_PAM_IMAGE_BUFFER_SIZE = 4ul * 1024ul * 1024ul * 1024ul; // defensive approach: set a reasonable max size for a PAM image namespace Orthanc {