[Development] [Announce] Security advisory: CVE-2026-79616 Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick
List for announcements regarding Qt releases and development via Announce
announce at qt-project.org
Wed Sep 23 09:56:19 CEST 2026
Out-of-bounds read vulnerability in the Qt Quick Context2D.path and PathSvg.path properties of the QQuickSvgParser component has been discovered and has been assigned the CVE id CVE-2026-79616.
Affected versions: from Qt 5.10 to Qt 6.8.8, from Qt 6.9.0 to Qt 6.11.1.
Impact: Out-of-bounds memory read while parsing the path string in a Qt Quick element's Context2D.path or PathSvg.path property may lead to a segmentation fault, a parse failure, or garbage being rendered. The input string used with Context2D.path is typically application controlled, but it might be sourced from anything that string data can be read from, including remote files. The issue only represents a vulnerability for applications that don't control the value assigned to Context2D.path.
CVSS 4.0 Score: 0.6 / Low
Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/R:U/RE:L/U:Green
Mitigation: Don't feed path strings from untrusted sources into the Context2D.path or PathSvg.path properties. This is generally the guidance with QML code.
Solution: Apply the following patch or update to Qt 6.8.9, Qt 6.11.2 or later.
Patches:
dev: https://codereview.qt-project.org/c/qt/qtdeclarative/+/754718
Qt 6.11: https://codereview.qt-project.org/c/qt/qtdeclarative/+/758197 or https://download.qt.io/official_releases/qt/6.11/CVE-2026-79616-qtdeclarative-6.11.diff
Qt 6.10: https://codereview.qt-project.org/c/qt/qtdeclarative/+/764154 or https://download.qt.io/official_releases/qt/6.10/CVE-2026-79616-qtdeclarative-6.10.diff
Qt 6.8: https://codereview.qt-project.org/c/qt/tqtc-qtdeclarative/+/758301 or https://download.qt.io/official_releases/qt/6.8/CVE-2026-79616-qtdeclarative-6.8.diff
Tero Pelkonen
Qt Group
Confidential
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.qt-project.org/pipermail/development/attachments/20260923/d5de6042/attachment-0001.htm>
-------------- next part --------------
_______________________________________________
Announce mailing list
Announce at qt-project.org
https://lists.qt-project.org/listinfo/announce
More information about the Development
mailing list