#1148673 qtbase-opensource-src: CVE-2026-76151

Package:
src:qtbase-opensource-src
Source:
src:qtbase-opensource-src
Submitter:
Moritz Mühlenhoff
Date:
2026-09-28 20:19:02 UTC
Severity:
normal
Tags:
#1148673#5
Date:
2026-09-21 21:05:22 UTC
From:
To:
Hi,

The following vulnerability was published for qtbase-opensource-src.

CVE-2026-76151[0]:
| Out-of-bounds read (buffer over-read) in the HTTP Cache-Control
| response header parsing in the QtNetwork module in Qt Group Qt 6.0.0
| through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to
| cause a denial of service (application crash) via an excessively
| large Cache-Control header value returned by an untrusted or
| compromised HTTP server to an application using
| QNetworkAccessManager. Only the client side of the connection is
| affected and 32-bit builds are not affected; the out-of-bounds
| access is read-only, with no information disclosure and no code
| execution.

https://codereview.qt-project.org/c/qt/qtbase/+/752129


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-76151
https://www.cve.org/CVERecord?id=CVE-2026-76151

Please adjust the affected versions in the BTS as needed.

#1148673#12
Date:
2026-09-22 20:58:38 UTC
From:
To:
Hi Moritz!

Maybe you meant to submit this bug to src:qt6-base?

The description says "Qt 6.0.0 through...", and the linked codereview
also says "Amends the port of QByteArray to qsizetype (6.0)".

#1148673#19
Date:
2026-09-28 20:18:25 UTC
From:
To:
Am Tue, Sep 22, 2026 at 11:58:38PM +0300 schrieb Dmitry Shachnev:

Apologies, I seem to have mixed up two Qt CVEs. This one is specific
to Qt6 indeed. I've updated the Debian Security Tracker as well.

Cheers,
        Moritz