Reason for update: Provided patch did not apply directly for the latest released versions of the supported branches. Earlier announcement was missing a link to a patch which needs to be applied before the patch which fixes the vulnerability. Patches available at download.qt.io have been updated. Please find the updated announcement below.
We apologize for the inconvenience. An out-of-bounds read (buffer over-read) vulnerability in the QTextCodec::codecForName() function of the Qt 5 Core Compatibility APIs (the Qt5Compat module) has been discovered and has been assigned the CVE id CVE-2026-9499 Affected versions: from Qt 4.0.0 to 6.8.7, and from Qt 6.9.0 to 6.11.0. This defect has existed since the introduction of the Qt5Compat module (Qt 6.0.0); the equivalent code path also exists from Qt 4.0.0 to Qt 5.15.19 LTS (Qt Core / qtbase). Impact: Passing a non-NUL-terminated QByteArray (for example, one created with QByteArray::fromRawData()) to QTextCodec::codecForName() can cause the codec-name matching routine to read past the end of the buffer, resulting in an incorrect codec match or, in the worst case, an application crash (denial of service). The over-read is bounded by the length of the longest codec-name candidate, and the bytes read are only compared against Qt's fixed internal codec list — no application or user data is exposed to an attacker. CVSS 4.0 Score: 6.3 (MEDIUM) Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N Mitigation: No practical runtime workaround is available short of applying the patch or upgrading. If your application does not construct codec-name QByteArrays via QByteArray::fromRawData(), you are not exposed to this issue. Solution: Apply the following patches, or update to Qt 6.8.8, Qt 6.11.1, or later. Patches: dev: https://codereview.qt-project.org/c/qt/qt5compat/+/723910 and https://codereview.qt-project.org/c/qt/qt5compat/+/723911 Qt 6.11: https://codereview.qt-project.org/c/qt/qt5compat/+/724270 and https://codereview.qt-project.org/c/qt/qt5compat/+/724348 or https://download.qt.io/official_releases/qt/6.11/CVE-2026-9499-qt5compat-6.11.diff Qt 6.10: https://codereview.qt-project.org/c/qt/qt5compat/+/724362 and https://codereview.qt-project.org/c/qt/qt5compat/+/724995 or https://download.qt.io/official_releases/qt/6.10/CVE-2026-9499-qt5compat-6.10.diff Qt 6.8: https://codereview.qt-project.org/c/qt/tqtc-qt5compat/+/725002 and https://codereview.qt-project.org/c/qt/tqtc-qt5compat/+/725112 or https://download.qt.io/official_releases/qt/6.8/CVE-2026-9499-qt5compat-6.8.diff Confidential
_______________________________________________ Announce mailing list [email protected] https://lists.qt-project.org/listinfo/announce
-- Development mailing list [email protected] https://lists.qt-project.org/listinfo/development
