#1148272 qtbase-opensource-src: CVE-2026-19248

#1148272#5
Date:
2026-09-18 15:44:11 UTC
From:
To:
Hi,

The following vulnerability was published for qtbase-opensource-src.

CVE-2026-19248[0]:
| QDomDocument XML parsing is vulnerable to a remotely-triggerable
| denial-of-service crash when processing untrusted input.

https://qt-project.atlassian.net/browse/QTBUG-147191
https://github.com/qt/qtbase/commit/1303f05b33bb777626644729dd3b1330f60ecb7f (6.10)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19248
https://www.cve.org/CVERecord?id=CVE-2026-19248

Please adjust the affected versions in the BTS as needed.

#1148272#10
Date:
2026-09-21 13:43:27 UTC
From:
To:
Hello,

Bug #1148272 in qtbase-opensource-src reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/qt-kde-team/qt/qtbase/-/commit/d5df7a2d3670559785c1125af125b8cd589f9b49
------------------------------------------------------------------------
Backport upstream patch to fix unbounded nesting depth in QDomNode.

Closes: #1148272.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148272

#1148272#17
Date:
2026-09-21 18:57:20 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
qtbase-opensource-src, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148272@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Dmitry Shachnev <mitya57@debian.org> (supplier of updated qtbase-opensource-src package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 21 Sep 2026 21:14:33 +0300
Source: qtbase-opensource-src
Architecture: source
Version: 5.15.19+dfsg-5
Distribution: unstable
Urgency: medium
Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Changed-By: Dmitry Shachnev <mitya57@debian.org>
Closes: 1148272
Changes:
 qtbase-opensource-src (5.15.19+dfsg-5) unstable; urgency=medium
 .
   * Backport upstream patch to fix unbounded nesting depth in QDomNode
     (CVE-2026-19248, closes: #1148272).
Checksums-Sha1:
 fe56a0e780ecdd1fef5d85a0153356941e6da142 5470 qtbase-opensource-src_5.15.19+dfsg-5.dsc
 8fbb0e0fbbfa26bc6521995352de917d35bbc196 234696 qtbase-opensource-src_5.15.19+dfsg-5.debian.tar.xz
 3f3e35d685f98f1db95acf376efcb6dd74fcc8b7 17853 qtbase-opensource-src_5.15.19+dfsg-5_source.buildinfo
Checksums-Sha256:
 15579dd646d4fe876dd9504d0bc2fff42c5fc81c733b34794ad544692c5cd218 5470 qtbase-opensource-src_5.15.19+dfsg-5.dsc
 175646c28a8fb9845747e0adf75999594f6a5ebdfa5587804298369508425ff6 234696 qtbase-opensource-src_5.15.19+dfsg-5.debian.tar.xz
 02094e87b77c9a97f3af02bc975a0723e453f557f2e955f56f790bb30f3a7738 17853 qtbase-opensource-src_5.15.19+dfsg-5_source.buildinfo
Files:
 15bd02ec5456ebc409620d7eb8ba706b 5470 libs optional qtbase-opensource-src_5.15.19+dfsg-5.dsc
 23c4ed67d80a50d1c64433871781985e 234696 libs optional qtbase-opensource-src_5.15.19+dfsg-5.debian.tar.xz
 90d7d3353c53430383acdbeea68dc039 17853 libs optional qtbase-opensource-src_5.15.19+dfsg-5_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJHBAEBCgAxFiEE8kKZ/xu8kBi5BqTLYCaTbS8ciuAFAmqxdRMTHG1pdHlhNTdA
ZGViaWFuLm9yZwAKCRBgJpNtLxyK4DNaD/98EZaa8jN5Yd3/rgrxeedhY/Bgctia
QuJEGrgWLuTZM/DWaZwCqe8PAVkRjdjXqaR0tDFf0VeCSMdSA4uUj1MOtKqtH0B2
ampuec5TLLkKRoG6yCb89cTYJsAAnV4Zs6NhSOoGc4x3RWI9gApjr8+rIa/Sl9CS
pYtCWFRVtAI4vNxt6m+KBIs/CQBrL7UiXM7/QqG6nw75kyvyDTMktKSA/87SED8K
k4Z/+dVoBAMQk8J7ZUiQWPq2WC4e4x1oZeML5yk0n4xXzUzm5qqbMhjmHCuUxiaK
t46m38SFva/FRmkR6P9i2pkOD3gvThrm59T2QcekMVPHYFOT4f8TstV0t7Ihf8IB
Myc97sWslG9mdqyfZmJojhkndv7loR3O9Vb2uvN/bHZ1mG/ZnyZdFDSiopNaMwLn
yDtFf44Y3l0Vg4pVrbbhRKkaTxcXtEYcPDVBSoYBnhjn0ajy0/t72IRfaG5OVRgn
vMaQONUR5WIE54o3F2WMZGd3cQYbm35R50QC9AIKZLz2ttwunlpcMzqBeycUf5bA
DDbSGaXOKGY1m44lxaxwPJW7C54KZsCp1Lgi3J1DFXNAuRGV3to1PIDTI3w89QlY
VCbJut+xsqgPWq/YSfgzXzAMMp0KEkXS5KiuT6kz1qcdhlxFOlwvhi8wvXF+UVGB
XhP/4DnxiEhzkg==
=6wC/
-----END PGP SIGNATURE-----