Reason for update: Provided patch did not apply directly for the latest 
released versions of the supported branches. Earlier announcement was missing a 
link to a patch which needs to be applied before the patch which fixes the 
vulnerability. Patches available at download.qt.io have been updated. Please 
find the updated announcement below.

We apologize for the inconvenience.



An out-of-bounds read (buffer over-read) vulnerability in the 
QTextCodec::codecForName() function of the Qt 5 Core Compatibility APIs (the 
Qt5Compat module) has been discovered and has been assigned the CVE id 
CVE-2026-9499

Affected versions: from Qt 4.0.0 to 6.8.7, and from Qt 6.9.0 to 6.11.0.

This defect has existed since the introduction of the Qt5Compat module (Qt 
6.0.0); the equivalent code path also exists from Qt 4.0.0 to Qt 5.15.19 LTS 
(Qt Core / qtbase).

Impact: Passing a non-NUL-terminated QByteArray (for example, one created with 
QByteArray::fromRawData()) to QTextCodec::codecForName() can cause the 
codec-name matching routine to read past the end of the buffer, resulting in an 
incorrect codec match or, in the worst case, an application crash (denial of 
service). The over-read is bounded by the length of the longest codec-name 
candidate, and the bytes read are only compared against Qt's fixed internal 
codec list — no application or user data is exposed to an attacker.

CVSS 4.0 Score: 6.3 (MEDIUM)

Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Mitigation: No practical runtime workaround is available short of applying the 
patch or upgrading. If your application does not construct codec-name 
QByteArrays via QByteArray::fromRawData(), you are not exposed to this issue.

Solution: Apply the following patches, or update to Qt 6.8.8, Qt 6.11.1, or 
later.

Patches:

dev: https://codereview.qt-project.org/c/qt/qt5compat/+/723910 and 
https://codereview.qt-project.org/c/qt/qt5compat/+/723911

Qt 6.11: https://codereview.qt-project.org/c/qt/qt5compat/+/724270 and 
https://codereview.qt-project.org/c/qt/qt5compat/+/724348 or 
https://download.qt.io/official_releases/qt/6.11/CVE-2026-9499-qt5compat-6.11.diff

Qt 6.10: https://codereview.qt-project.org/c/qt/qt5compat/+/724362 and 
https://codereview.qt-project.org/c/qt/qt5compat/+/724995 or 
https://download.qt.io/official_releases/qt/6.10/CVE-2026-9499-qt5compat-6.10.diff

Qt 6.8: https://codereview.qt-project.org/c/qt/tqtc-qt5compat/+/725002 and 
https://codereview.qt-project.org/c/qt/tqtc-qt5compat/+/725112 or 
https://download.qt.io/official_releases/qt/6.8/CVE-2026-9499-qt5compat-6.8.diff



Confidential
_______________________________________________
Announce mailing list
[email protected]
https://lists.qt-project.org/listinfo/announce
-- 
Development mailing list
[email protected]
https://lists.qt-project.org/listinfo/development

Reply via email to