Public bug reported:

[ Impact ]

Qt 6.10 apps crash with SIGSEGV in FcCharSetHasChar() when a fontconfig
fallback pattern has no charset.
QFontEngineMultiFontConfig::shouldLoadFontEngineForCharacter() ignores
the result of FcPatternGetCharSet() and passes the uninitialized
FcCharSet pointer to FcCharSetHasChar() (0xfefefefefefefefe in this
build, which fills uninitialized locals with 0xFE).

Charset-less patterns come from fontconfig caches written by a
fontconfig built with the fontations backend: Google Chrome 154 bundles
one and links its cache for the system fontconfig
(https://gitlab.freedesktop.org/fontconfig/fontconfig/-/work_items/565),
and the Kubuntu 26.04.1 image shipped such a cache for fonts-katex.
These placeholders then win fc-match for any family, and plasmashell,
krunner, konsole, systemsettings and other Qt apps crash on their first
glyph fallback. See bug 2168311 (Plasma does not start) and bug 2168420.

Qt fixed this upstream in qtbase commit
80ddc8dee6a05cd619085e29fc21ff92c4b877a8 "Fix crash when fontconfig
fallback pattern has no charset" (merged 2026-08-12). It has "Pick-to:
6.12 6.11 6.8", which leaves out 6.10, so 26.04 LTS (6.10.2+dfsg-7)
keeps the crash. The patch changes 5 lines in
src/gui/text/unix/qfontenginemultifontconfig.cpp:

-        FcCharSet *charSet;
-        FcPatternGetCharSet(matchPattern, FC_CHARSET, 0, &charSet);
-        charSetHasChar = FcCharSetHasChar(charSet, ucs4);
+        FcCharSet *charSet = nullptr;
+        if (FcPatternGetCharSet(matchPattern, FC_CHARSET, 0, &charSet) == 
FcResultMatch
+            && charSet != nullptr) {
+            charSetHasChar = FcCharSetHasChar(charSet, ucs4);
+        }

[ Test Plan ]

1. Make a charset-less pattern win matching: install fonts-katex (default on 
Kubuntu) and start Google Chrome 154 once, or copy its 
~/.cache/fontconfig/<md5>-le64.cache-12 files as <md5>-le64.cache-9.
2. Check that `fc-match monospace` returns a KaTeX .woff file.
3. Run the PyQt6 reproducer from fontconfig#565 with QT_QPA_PLATFORM=offscreen 
(a QTextLayout with CJK and emoji text), or print U+FFFD in Konsole.
Without the fix: SIGSEGV in FcCharSetHasChar(). With the fix: the text is laid 
out, no crash.

[ Where problems could occur ]

Only the fontconfig charset check in QFontEngineMultiFontConfig changes.
When a fallback pattern has no charset, Qt now keeps its existing
optimistic default (load the font engine), as it already does when there
is no match pattern, and the font engine decides glyph coverage. A
regression would show up as a different fallback font being loaded for
some characters.

[ Other Info ]

Backtrace (plasmashell 15:46 and konsole 19:53 on 2026-09-24, same stack):
#0 ?? () libfontconfig.so.1 +0xc4fc
#1 FcCharSetHasChar () libfontconfig.so.1
#2 QFontEngineMultiFontConfig::shouldLoadFontEngineForCharacter(int, unsigned 
int) const
#3 QFontEngineMulti::stringToCMap(...)
#4 QTextEngine::shapeText(int) const

From the konsole core: charset pointer 0xfefefefefefefefe, ucs4 U+FFFD,
and the cached fallback pattern held only family="DejaVu Sans Mono"
(copied from the request),
file=/usr/share/fonts/truetype/katex/KaTeX_AMS-Regular.woff and
fontwrapper=WOFF.

Versions: libqt6gui6 6.10.2+dfsg-7, fontconfig 2.17.1-3ubuntu1, plasma-
workspace 4:6.6.6-0ubuntu0.1, konsole 4:25.12.3-0ubuntu1.

(Found with the help of an AI assistant, Claude; the cores, backtraces
and tests are from my machine.)

** Affects: qt6-base (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168504

Title:
  Qt apps crash in FcCharSetHasChar() on glyph fallback when the
  fallback pattern has no charset; please backport qtbase 80ddc8dee6a0

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/qt6-base/+bug/2168504/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to