CVE-2026-79616: 
Qt Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-79616 is an out-of-bounds read vulnerability in Qt Quick's SVG path parsing, specifically affecting the Context2D.path and PathSvg.path properties when processing untrusted SVG path strings. It affects Qt versions 5.10.0 through 6.8.8 and 6.9.0 through 6.11.1. The vulnerability was published on September 23, 2026, and has a CVSS v3.1 base score of 4.4 (Medium) and a CVSS v4.0 base score of 0.6 (Low) (GitHub Advisory, Red Hat Bugzilla).

Détails techniques

The root cause is an out-of-bounds read (CWE-125) in the SVG path string parser within the qtdeclarative module of Qt Quick. When a maliciously crafted SVG path string is passed to Context2D.path or PathSvg.path, the parser reads beyond the intended buffer boundary without adequate bounds checking. Exploitation requires local access, low privileges, user interaction, and specific attack preconditions (attack requirements: present), making it a relatively constrained attack surface. A patch commit is available at the Qt project code review system (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation can cause a denial of service (application crash) due to the out-of-bounds read in the SVG path parser, impacting availability of applications built on Qt Quick. There is no confidentiality or integrity impact assessed for the vulnerable system, and no subsequent system impact is expected. The scope is limited to the local system running the affected Qt Quick application (GitHub Advisory, Red Hat Bugzilla).

Exploitabilité

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.15%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment confirms exploitation status as "none" (GitHub Advisory).

Atténuation et solutions de contournement

Users should update Qt to a version that includes the fix for this vulnerability — specifically, versions beyond 6.8.8 (in the 5.10.x–6.8.x branch) and beyond 6.11.1 (in the 6.9.x–6.11.x branch). The patch is available via the Qt project code review at https://codereview.qt-project.org/c/qt/qtdeclarative/+/754718. As a workaround, applications should validate and sanitize all SVG path input from untrusted sources before passing it to Context2D.path or PathSvg.path (GitHub Advisory, Red Hat Bugzilla).

Réactions de la communauté

Qt published an official security advisory on their blog at the time of disclosure. Red Hat tracked the issue via Bugzilla (Bug 2539304) and classified it as medium severity. No significant broader community or social media discussion has been observed beyond standard vulnerability aggregator coverage (Qt Security Advisory, Red Hat Bugzilla).

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Fixe

bookworm

qtdeclarative-opensource-src

Affecté

sid

qtdeclarative-opensource-src

Affecté

trixie

qtdeclarative-opensource-src

Affecté

Ubuntu

Inconnu

devel

qt6-declarative

Inconnu

jammy

qt6-declarative

Inconnu

jammy (esm-apps)

qt6-declarative

Inconnu

noble

qt6-declarative

Inconnu

noble (esm-apps)

qt6-declarative

Inconnu

resolute

qt6-declarative

Inconnu

resolute (esm-apps)

qt6-declarative

Inconnu

RHEL / CentOS

Affecté

RHEL 8

qt5-qtdeclarative.src

Affecté

RHEL 9

qt5-qtdeclarative.src

Affecté

RHEL 10

qt6-qtdeclarative.src

Affecté

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Qt Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-19395MEDIUM6.6
  • Qt logoQt
  • qt6
NonNonOct 05, 2026
CVE-2026-76151MEDIUM4.6
  • Qt logoQt
  • qt5-qtbase
NonOuiSep 16, 2026
CVE-2026-79680MEDIUM4.5
  • Qt logoQt
  • cpe:2.3:a:qt:qt
NonOuiSep 24, 2026
CVE-2026-78253LOW2.3
  • Qt logoQt
  • qt6.src
NonOuiSep 23, 2026
CVE-2026-79616LOW0.6
  • Qt logoQt
  • qt5-qtdeclarative-examples
NonOuiSep 23, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités