- Package:
- src:qtbase-opensource-src
- Source:
- src:qtbase-opensource-src
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-29 08:51:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for Qt5Compat module from Qt. CVE-2026-9499[0]: | An out-of-bounds read (buffer over-read) vulnerability exists in | QTextCodec::codecForName() in Qt. When the function is called with a | QByteArray that is not NUL-terminated (for example, one created with | QByteArray::fromRawData()), the codec-name matching routine reads | past the end of the supplied buffer. In most cases this results in | an incorrect text codec being selected; in the worst case, if the | over-read reaches unmapped memory, the process crashes (denial of | service). The over-read is bounded by the length of the longest | codec-name candidate, and the out-of-bounds bytes are only compared | internally against Qt's fixed list of codec names, so no data is | disclosed to an attacker. Applications that do not pass non-NUL- | terminated QByteArrays to QTextCodec::codecForName() are not | exposed. The affected code resides in the Qt5Compat module from Qt | 6.0.0 onward, and in Qt Core (qtbase) in Qt 4.x and Qt 5.x. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-9499 https://www.cve.org/CVERecord?id=CVE-2026-9499 Please adjust the affected versions in the BTS as needed.
Hello, Bug #1142691 in qtbase-opensource-src reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/qt-kde-team/qt/qtbase/-/commit/ed79556b83d4f2b35a83ee11372002ebf4b116c1 ------------------------------------------------------------------------ Backport upstream patch to avoid read-past-buffer in QTextCodec::codecForName(). Closes: #1142691. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1142691
We believe that the bug you reported is fixed in the latest version of
qtbase-opensource-src, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142691@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Dmitry Shachnev <mitya57@debian.org> (supplier of updated qtbase-opensource-src package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 29 Jul 2026 11:26:16 +0300
Source: qtbase-opensource-src
Architecture: source
Version: 5.15.19+dfsg-4
Distribution: unstable
Urgency: medium
Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Changed-By: Dmitry Shachnev <mitya57@debian.org>
Closes: 1142691
Changes:
qtbase-opensource-src (5.15.19+dfsg-4) unstable; urgency=medium
.
* Backport upstream patch to avoid read-past-buffer in
QTextCodec::codecForName() (CVE-2026-9499, closes: #1142691).
Checksums-Sha1:
94dabe0c3332c93cabe924cd147b3ab15cf8f9e9 5470 qtbase-opensource-src_5.15.19+dfsg-4.dsc
b25336358eab27e2d442a290633672d53adbb19e 234004 qtbase-opensource-src_5.15.19+dfsg-4.debian.tar.xz
dc5aab35b2b1d9f4349290fd69ba9374bb44a59e 17866 qtbase-opensource-src_5.15.19+dfsg-4_source.buildinfo
Checksums-Sha256:
16b60d4650ce3bc1aa31cf34d4cf00c7c50d2003173defc4a2322ef381c466d4 5470 qtbase-opensource-src_5.15.19+dfsg-4.dsc
286ee7112908ba8d6666cb29304838320fcad17f3cedf0608188c4c594537348 234004 qtbase-opensource-src_5.15.19+dfsg-4.debian.tar.xz
3cddb259fea57032582f8dd191baba699e28f970a9e0e09557a2016e624c3d59 17866 qtbase-opensource-src_5.15.19+dfsg-4_source.buildinfo
Files:
5cce7e447f04396f318bdf3d8f09a31d 5470 libs optional qtbase-opensource-src_5.15.19+dfsg-4.dsc
b439c0dd844061839662b74ea8cc6926 234004 libs optional qtbase-opensource-src_5.15.19+dfsg-4.debian.tar.xz
5b53d0c77f014a3d8f2baa0342f54db6 17866 libs optional qtbase-opensource-src_5.15.19+dfsg-4_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJHBAEBCgAxFiEE8kKZ/xu8kBi5BqTLYCaTbS8ciuAFAmppubsTHG1pdHlhNTdA
ZGViaWFuLm9yZwAKCRBgJpNtLxyK4LU0EAC4W8VeSme/kfPIdTjciyv81sh8KWYW
LaoxlUzGzLEYt4psjMM6azzcznd3y7Z0o8pmkCFNbtUStGgPMe0XSLwS+1XqkiSp
RNNd1+VUdqXvsnKfHBvG7aOvyn1fLDe0QK0aFt1Jn9R81hwfk06QFTKMip1WUi+E
Vq23hg9JxBOLBonEaLuD1eVNUKSb9W6icaMqpTnXN+yMjZ7nvRnXfzOjRwIIjxo1
5iULIbNoHK8RK8a6LbyzH4QL6XEAp7pL8ubLokpVWu7JY/B8qgf5knqDTPJrtZB5
/bvGQTv7rzYF6Hs6JXE+IK6IBOm04h1vJZR5wTh2JRY39W4SFB2zUn1FTbJUAhsK
UTnYYDh01KBHX5zE1BtvDnaUyP8ESl4b8QnJY5kWqHA/gEneaxNX9U4Mua9lF8v4
V9v8ZgBBlQjuI3p3Lml7VUjMwZVsOTb48Rrrfi8xZ5qZQKYHQrIaQ3zPrlVApEZJ
PM2PAafeaWMChhEHahWJGrXQ3t+rOK7wxdVBT7pdJnuLMBo3K0WOmiua+LT4wXGt
WnULl0RXaf5DN6npD3oxgJ2axmhHIrtBnVugfXIs/lN67lWksRR6nH1DHK6QK5Xi
y6n+Ru5tlH26RHLjKceLNpgKmmrmpqByR//NFHeCUhKWy3LcaPw09VvhSLKBT187
iYENPsA5S9gBCw==
=BPO/
-----END PGP SIGNATURE-----