Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-20567

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-20567: qt6-qtdeclarative security update (IMPORTANT)

[6.10.1-1.1]

  • VectorImage: sanitize source string used in output (CVE-2025-14576) Resolves: RHEL-173494

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

qt6-qtdeclarative

6.10.1-1.el10_2.1

qt6-qtdeclarative-devel

6.10.1-1.el10_2.1

qt6-qtdeclarative-examples

6.10.1-1.el10_2.1

qt6-qtdeclarative-static

6.10.1-1.el10_2.1

Oracle Linux x86_64

qt6-qtdeclarative

6.10.1-1.el10_2.1

qt6-qtdeclarative-devel

6.10.1-1.el10_2.1

qt6-qtdeclarative-examples

6.10.1-1.el10_2.1

qt6-qtdeclarative-static

6.10.1-1.el10_2.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
redhat
3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
nvd
3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
debian
3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary ...

rocky
около 2 месяцев назад

Important: qt6-qtdeclarative security update