- Package:
- src:qt6-5compat
- Source:
- src:qt6-5compat
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-26 13:37:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for Qt5Compat module from Qt. CVE-2026-9499[0]: | An out-of-bounds read (buffer over-read) vulnerability exists in | QTextCodec::codecForName() in Qt. When the function is called with a | QByteArray that is not NUL-terminated (for example, one created with | QByteArray::fromRawData()), the codec-name matching routine reads | past the end of the supplied buffer. In most cases this results in | an incorrect text codec being selected; in the worst case, if the | over-read reaches unmapped memory, the process crashes (denial of | service). The over-read is bounded by the length of the longest | codec-name candidate, and the out-of-bounds bytes are only compared | internally against Qt's fixed list of codec names, so no data is | disclosed to an attacker. Applications that do not pass non-NUL- | terminated QByteArrays to QTextCodec::codecForName() are not | exposed. The affected code resides in the Qt5Compat module from Qt | 6.0.0 onward, and in Qt Core (qtbase) in Qt 4.x and Qt 5.x. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-9499 https://www.cve.org/CVERecord?id=CVE-2026-9499 Please adjust the affected versions in the BTS as needed.
We believe that the bug you reported is fixed in the latest version of qt6-5compat, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1142690@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Patrick Franz <deltaone@debian.org> (supplier of updated qt6-5compat package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sun, 26 Jul 2026 15:21:50 +0200 Source: qt6-5compat Architecture: source Version: 6.10.2-4 Distribution: unstable Urgency: medium Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org> Changed-By: Patrick Franz <deltaone@debian.org> Closes: 1142690 Changes: qt6-5compat (6.10.2-4) unstable; urgency=medium . [ Patrick Franz ] * Backport patch to fix CVE-2026-9499 (Closes: #1142690). Checksums-Sha1: 3bb8c4b765411b5e1f997ad794ea012ab2ded617 2809 qt6-5compat_6.10.2-4.dsc 523db8ba229752bfe96d3491236ec14f5872058b 11056 qt6-5compat_6.10.2-4.debian.tar.xz 00f8bd255c090d18b08dff04032f93e40e46a4eb 11536 qt6-5compat_6.10.2-4_source.buildinfo Checksums-Sha256: fe7510d089985981481d8cbcbedd8cccc47eaef16e96c1160e54c88729f34b93 2809 qt6-5compat_6.10.2-4.dsc 2eef4ebf9996084c0646b69e7e8f2a0b3616c52b4863b4474d40b85496aad533 11056 qt6-5compat_6.10.2-4.debian.tar.xz 0045317ef6c796785acae2a8cc68a035ee9f8b7ede132bd08cd045e3f2acd646 11536 qt6-5compat_6.10.2-4_source.buildinfo Files: a450827b23af93ee5c2f74684c5138a3 2809 libs optional qt6-5compat_6.10.2-4.dsc 93de79a384d83b5b92948b9f6fc3b8bd 11056 libs optional qt6-5compat_6.10.2-4.debian.tar.xz 3e93363ed550f522c809e7a49b7c0e1d 11536 libs optional qt6-5compat_6.10.2-4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYodBXDR68cxZHu3Knp96YDB3/lYFAmpmCmYACgkQnp96YDB3 /lYgLBAApV2UwVCDl/iZzQmUOmVGS+mynfmw4+rxCcZelRl9/aBD84cG1WL1LUa2 CZkuyo9CKdQrY8yHXZPrcb1+6zZeDKg9QyqeT0d7G/cOKJYKCxBwiGalNKd6Pz3G 63feWr53luLeQrrZbq5UVAt9FM6XrTKWBdMxVPetRkqZukFE/DTI+eUBVl9GLVMD owT9m+AauV0wXJ4tYPCAFfcedfCSgku55Poy24nSldaLgLSaa8CKZhQBenZ33IVD wnrHXOqdnDorF0mvN/NIZxnLc5sKuxqfjIS1Qu0LINfsSuSgH15P20bg4TWqvMzu VHRbKNjTybu5/Sk2DlxqKyF1QZyrqw2XoWtK3lccm/12IURhJRPJRnCa3Po0AU1p mDWS2imLgcmxXzm68w10L9t2jQ+ntyaTx1Cz5XHNffi6kBp+mqNybPKZALGEui5s 9CJVVKUTDvkOcINZRG8sTSo/bRZ9hqODa2ZPBEHaIBwkdt3nmjIYM2FSI4UeyX9i 2EL81QWf17ABNubAkUDbLuAfERT257zm0Dwg3c9Y91/y8EpTcxBjpoA1hmUGOWhK Q10EAKgRkbQ8B9Qwc51ItSD5N655/+LjaINxyHqRzirx1/302apT2stXLfS/cMrn SJpHgcWoojT/qJ7+ksTysXlowkLdXL2f7jlQXyhYeb2zxmLF0nk= =61qX -----END PGP SIGNATURE-----