Your message dated Sun, 26 Jul 2026 13:34:26 +0000
with message-id <[email protected]>
and subject line Bug#1142690: fixed in qt6-5compat 6.10.2-4
has caused the Debian Bug report #1142690,
regarding qt6-5compat: CVE-2026-9499
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142690: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142690
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: qt6-5compat
Version: 6.10.2-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: clone -1 -2
Control: reassign -2 src:qtbase-opensource-src 5.15.19+dfsg-3
Control: retitle -2 qtbase-opensource-src: CVE-2026-9499

Hi,

The following vulnerability was published for Qt5Compat module from
Qt.

CVE-2026-9499[0]:
| An out-of-bounds read (buffer over-read) vulnerability exists in
| QTextCodec::codecForName() in Qt. When the function is called with a
| QByteArray that is not NUL-terminated (for example, one created with
| QByteArray::fromRawData()), the codec-name matching routine reads
| past the end of the supplied buffer. In most cases this results in
| an incorrect text codec being selected; in the worst case, if the
| over-read reaches unmapped memory, the process crashes (denial of
| service). The over-read is bounded by the length of the longest
| codec-name candidate, and the out-of-bounds bytes are only compared
| internally against Qt's fixed list of codec names, so no data is
| disclosed to an attacker. Applications that do not pass non-NUL-
| terminated QByteArrays to QTextCodec::codecForName() are not
| exposed. The affected code resides in the Qt5Compat module from Qt
| 6.0.0 onward, and in Qt Core (qtbase) in Qt 4.x and Qt 5.x.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-9499
    https://www.cve.org/CVERecord?id=CVE-2026-9499

Please adjust the affected versions in the BTS as needed.



-- System Information:
Debian Release: forky/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 7.1.3+deb14-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

--- End Message ---
--- Begin Message ---
Source: qt6-5compat
Source-Version: 6.10.2-4
Done: Patrick Franz <[email protected]>

We believe that the bug you reported is fixed in the latest version of
qt6-5compat, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Franz <[email protected]> (supplier of updated qt6-5compat package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 26 Jul 2026 15:21:50 +0200
Source: qt6-5compat
Architecture: source
Version: 6.10.2-4
Distribution: unstable
Urgency: medium
Maintainer: Debian Qt/KDE Maintainers <[email protected]>
Changed-By: Patrick Franz <[email protected]>
Closes: 1142690
Changes:
 qt6-5compat (6.10.2-4) unstable; urgency=medium
 .
   [ Patrick Franz ]
   * Backport patch to fix CVE-2026-9499 (Closes: #1142690).
Checksums-Sha1:
 3bb8c4b765411b5e1f997ad794ea012ab2ded617 2809 qt6-5compat_6.10.2-4.dsc
 523db8ba229752bfe96d3491236ec14f5872058b 11056 
qt6-5compat_6.10.2-4.debian.tar.xz
 00f8bd255c090d18b08dff04032f93e40e46a4eb 11536 
qt6-5compat_6.10.2-4_source.buildinfo
Checksums-Sha256:
 fe7510d089985981481d8cbcbedd8cccc47eaef16e96c1160e54c88729f34b93 2809 
qt6-5compat_6.10.2-4.dsc
 2eef4ebf9996084c0646b69e7e8f2a0b3616c52b4863b4474d40b85496aad533 11056 
qt6-5compat_6.10.2-4.debian.tar.xz
 0045317ef6c796785acae2a8cc68a035ee9f8b7ede132bd08cd045e3f2acd646 11536 
qt6-5compat_6.10.2-4_source.buildinfo
Files:
 a450827b23af93ee5c2f74684c5138a3 2809 libs optional qt6-5compat_6.10.2-4.dsc
 93de79a384d83b5b92948b9f6fc3b8bd 11056 libs optional 
qt6-5compat_6.10.2-4.debian.tar.xz
 3e93363ed550f522c809e7a49b7c0e1d 11536 libs optional 
qt6-5compat_6.10.2-4_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEYodBXDR68cxZHu3Knp96YDB3/lYFAmpmCmYACgkQnp96YDB3
/lYgLBAApV2UwVCDl/iZzQmUOmVGS+mynfmw4+rxCcZelRl9/aBD84cG1WL1LUa2
CZkuyo9CKdQrY8yHXZPrcb1+6zZeDKg9QyqeT0d7G/cOKJYKCxBwiGalNKd6Pz3G
63feWr53luLeQrrZbq5UVAt9FM6XrTKWBdMxVPetRkqZukFE/DTI+eUBVl9GLVMD
owT9m+AauV0wXJ4tYPCAFfcedfCSgku55Poy24nSldaLgLSaa8CKZhQBenZ33IVD
wnrHXOqdnDorF0mvN/NIZxnLc5sKuxqfjIS1Qu0LINfsSuSgH15P20bg4TWqvMzu
VHRbKNjTybu5/Sk2DlxqKyF1QZyrqw2XoWtK3lccm/12IURhJRPJRnCa3Po0AU1p
mDWS2imLgcmxXzm68w10L9t2jQ+ntyaTx1Cz5XHNffi6kBp+mqNybPKZALGEui5s
9CJVVKUTDvkOcINZRG8sTSo/bRZ9hqODa2ZPBEHaIBwkdt3nmjIYM2FSI4UeyX9i
2EL81QWf17ABNubAkUDbLuAfERT257zm0Dwg3c9Y91/y8EpTcxBjpoA1hmUGOWhK
Q10EAKgRkbQ8B9Qwc51ItSD5N655/+LjaINxyHqRzirx1/302apT2stXLfS/cMrn
SJpHgcWoojT/qJ7+ksTysXlowkLdXL2f7jlQXyhYeb2zxmLF0nk=
=61qX
-----END PGP SIGNATURE-----

Attachment: pgpP0PBrvUbhU.pgp
Description: PGP signature


--- End Message ---

Reply via email to