Source: qtbase-opensource-src
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for qtbase-opensource-src.

CVE-2026-76151[0]:
| Out-of-bounds read (buffer over-read) in the HTTP Cache-Control
| response header parsing in the QtNetwork module in Qt Group Qt 6.0.0
| through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to
| cause a denial of service (application crash) via an excessively
| large Cache-Control header value returned by an untrusted or
| compromised HTTP server to an application using
| QNetworkAccessManager. Only the client side of the connection is
| affected and 32-bit builds are not affected; the out-of-bounds
| access is read-only, with no information disclosure and no code
| execution.

https://codereview.qt-project.org/c/qt/qtbase/+/752129


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-76151
    https://www.cve.org/CVERecord?id=CVE-2026-76151

Please adjust the affected versions in the BTS as needed.

Reply via email to