Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9499

Опубликовано: 21 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matching routine reads past the end of the supplied buffer. In most cases this results in an incorrect text codec being selected; in the worst case, if the over-read reaches unmapped memory, the process crashes (denial of service). The over-read is bounded by the length of the longest codec-name candidate, and the out-of-bounds bytes are only compared internally against Qt's fixed list of codec names, so no data is disclosed to an attacker. Applications that do not pass non-NUL-terminated QByteArrays to QTextCodec::codecForName() are not exposed. The affected code resides in the Qt5Compat module from Qt 6.0.0 onward, and in Qt Core (qtbase) in Qt 4.x and Qt 5.x.

A flaw was found in Qt, a popular software development framework. This vulnerability, an out-of-bounds read, occurs in the QTextCodec::codecForName() function when it processes specially crafted input that is not properly terminated. An attacker could exploit this to cause the application to select an incorrect text encoding, or in the worst case, trigger a crash, leading to a denial of service. This flaw does not result in the disclosure of sensitive information.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qtOut of support scope
Red Hat Enterprise Linux 6qt3Not affected
Red Hat Enterprise Linux 7qtAffected
Red Hat Enterprise Linux 7qt3Not affected
Red Hat Hardened Imagesqt5Affected
Red Hat Enterprise Linux 10qt6-qt5compatFixedRHSA-2026:6581609.09.2026
Red Hat Enterprise Linux 8qt5-qtbaseFixedRHSA-2026:6589709.09.2026
Red Hat Enterprise Linux 9qt5-qtbaseFixedRHSA-2026:6599309.09.2026
Red Hat Hardened Imagesqt6-main-6.11.1-2.hum1FixedRHSA-2026:4138918.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2503641qt: Qt: Denial of Service via out-of-bounds read in text codec handling

7.5 High

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matching routine reads past the end of the supplied buffer. In most cases this results in an incorrect text codec being selected; in the worst case, if the over-read reaches unmapped memory, the process crashes (denial of service). The over-read is bounded by the length of the longest codec-name candidate, and the out-of-bounds bytes are only compared internally against Qt's fixed list of codec names, so no data is disclosed to an attacker. Applications that do not pass non-NUL-terminated QByteArrays to QTextCodec::codecForName() are not exposed. The affected code resides in the Qt5Compat module from Qt 6.0.0 onward, and in Qt Core (qtbase) in Qt 4.x and Qt 5.x.

nvd
около 2 месяцев назад

An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matching routine reads past the end of the supplied buffer. In most cases this results in an incorrect text codec being selected; in the worst case, if the over-read reaches unmapped memory, the process crashes (denial of service). The over-read is bounded by the length of the longest codec-name candidate, and the out-of-bounds bytes are only compared internally against Qt's fixed list of codec names, so no data is disclosed to an attacker. Applications that do not pass non-NUL-terminated QByteArrays to QTextCodec::codecForName() are not exposed. The affected code resides in the Qt5Compat module from Qt 6.0.0 onward, and in Qt Core (qtbase) in Qt 4.x and Qt 5.x.

debian
около 2 месяцев назад

An out-of-bounds read (buffer over-read) vulnerability exists in QText ...

rocky
5 дней назад

Important: qt5-qtbase security update

rocky
5 дней назад

Important: qt5-qtbase security update

7.5 High

CVSS3