Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Security advisory: CVE-2026-79616 Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick

Дата публикации: 23-09-2026 07:54:55

Out-of-bounds read vulnerability in the Qt Quick Context2D.path and PathSvg.path properties of the QQuickSvgParser component has been discovered and has been assigned the CVE id CVE-2026-79616. 

Основное содержимое страницы с новостью.

Out-of-bounds read vulnerability in the Qt Quick Context2D.path and PathSvg.path properties of the QQuickSvgParser component has been discovered and has been assigned the CVE id CVE-2026-79616. 

Affected versions: from Qt 5.10 to Qt 6.8.8, from Qt 6.9.0 to Qt 6.11.1. 

Impact: Out-of-bounds memory read while parsing the path string in a Qt Quick element's Context2D.path or PathSvg.path property may lead to a segmentation fault, a parse failure, or garbage being rendered. The input string used with Context2D.path is typically application controlled, but it might be sourced from anything that string data can be read from, including remote files. The issue only represents a vulnerability for applications that don't control the value assigned to Context2D.path. 

CVSS 4.0 Score: 0.6 / Low 

Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/R:U/RE:L/U:Green

Mitigation: Don't feed path strings from untrusted sources into the Context2D.path or PathSvg.path properties. This is generally the guidance with QML code. 

Solution: Apply the following patch or update to Qt 6.8.9, Qt 6.11.2 or later. 

Related Articles

Security advisory: CVE-2026-78253 Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt

Security advisory: CVE-2026-78253 Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt

A denial-of-service (stack-exhaustion) vulnerability in the..

Read Article

Security advisory: CVE-2026-76151 out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)

Security advisory: CVE-2026-76151 out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)

An out-of-bounds read (buffer over-read) vulnerability in the HTTP..

Read Article

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Security advisory: CVE-2026-78253 Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt014.3623-09-2026
2OpenSSL Security Advisory06.6213-08-2026
3openSUSE Leap 16.0 libslirp Moderate TCP Leak Vulnerability 2026-21216-10503-07-2026
4CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document013.1313-08-2026
5CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for011.5413-08-2026
6openSUSE GStreamer-Plugins-Bad Important Out-of-Bounds DoS CVE-2026-527190503-07-2026
7SUSE glibc Moderate Buffer Overflow Vulnerability 2026-23738-101021-09-2026
8Canvas2D: New QML canvas element using Qt Canvas Painter09.718-09-2026
9Qt Creator 20.0.2 released09.0323-09-2026
10Qt WebEngine Separate Release014.724-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.21. Источник: www.qt.io.