Out-of-bounds read vulnerability in the Qt Quick Context2D.path and PathSvg.path properties of the QQuickSvgParser component has been discovered and has been assigned the CVE id CVE-2026-79616. Affected versions: from Qt 5.10 to Qt 6.8.8, from Qt 6.9.0 to Qt 6.11.1.
Impact: Out-of-bounds memory read while parsing the path string in a Qt Quick element's Context2D.path or PathSvg.path property may lead to a segmentation fault, a parse failure, or garbage being rendered. The input string used with Context2D.path is typically application controlled, but it might be sourced from anything that string data can be read from, including remote files. The issue only represents a vulnerability for applications that don't control the value assigned to Context2D.path. CVSS 4.0 Score: 0.6 / Low Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/R:U/RE:L/U:Green Mitigation: Don't feed path strings from untrusted sources into the Context2D.path or PathSvg.path properties. This is generally the guidance with QML code. Solution: Apply the following patch or update to Qt 6.8.9, Qt 6.11.2 or later. Patches: dev: https://codereview.qt-project.org/c/qt/qtdeclarative/+/754718 Qt 6.11: https://codereview.qt-project.org/c/qt/qtdeclarative/+/758197 or https://download.qt.io/official_releases/qt/6.11/CVE-2026-79616-qtdeclarative-6.11.diff Qt 6.10: https://codereview.qt-project.org/c/qt/qtdeclarative/+/764154 or https://download.qt.io/official_releases/qt/6.10/CVE-2026-79616-qtdeclarative-6.10.diff Qt 6.8: https://codereview.qt-project.org/c/qt/tqtc-qtdeclarative/+/758301 or https://download.qt.io/official_releases/qt/6.8/CVE-2026-79616-qtdeclarative-6.8.diff Tero Pelkonen Qt Group Confidential
_______________________________________________ Announce mailing list [email protected] https://lists.qt-project.org/listinfo/announce
-- Development mailing list [email protected] https://lists.qt-project.org/listinfo/development
