Control: tags -1 + moreinfo Hi Moritz!
On Mon, Sep 21, 2026 at 11:05:22PM +0200, Moritz Mühlenhoff wrote: > Source: qtbase-opensource-src > X-Debbugs-CC: [email protected] > Severity: important > Tags: security > > Hi, > > The following vulnerability was published for qtbase-opensource-src. > > CVE-2026-76151[0]: > | Out-of-bounds read (buffer over-read) in the HTTP Cache-Control > | response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 > | through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to > | cause a denial of service (application crash) via an excessively > | large Cache-Control header value returned by an untrusted or > | compromised HTTP server to an application using > | QNetworkAccessManager. Only the client side of the connection is > | affected and 32-bit builds are not affected; the out-of-bounds > | access is read-only, with no information disclosure and no code > | execution. > > https://codereview.qt-project.org/c/qt/qtbase/+/752129 Maybe you meant to submit this bug to src:qt6-base? The description says "Qt 6.0.0 through...", and the linked codereview also says "Amends the port of QByteArray to qsizetype (6.0)". -- Dmitry Shachnev
signature.asc
Description: PGP signature

