
PEACH
Un cadre d’isolation des locataires
CVE-2026-79616 is an out-of-bounds read vulnerability in Qt Quick's SVG path parsing, specifically affecting the Context2D.path and PathSvg.path properties when processing untrusted SVG path strings. It affects Qt versions 5.10.0 through 6.8.8 and 6.9.0 through 6.11.1. The vulnerability was published on September 23, 2026, and has a CVSS v3.1 base score of 4.4 (Medium) and a CVSS v4.0 base score of 0.6 (Low) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an out-of-bounds read (CWE-125) in the SVG path string parser within the qtdeclarative module of Qt Quick. When a maliciously crafted SVG path string is passed to Context2D.path or PathSvg.path, the parser reads beyond the intended buffer boundary without adequate bounds checking. Exploitation requires local access, low privileges, user interaction, and specific attack preconditions (attack requirements: present), making it a relatively constrained attack surface. A patch commit is available at the Qt project code review system (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation can cause a denial of service (application crash) due to the out-of-bounds read in the SVG path parser, impacting availability of applications built on Qt Quick. There is no confidentiality or integrity impact assessed for the vulnerable system, and no subsequent system impact is expected. The scope is limited to the local system running the affected Qt Quick application (GitHub Advisory, Red Hat Bugzilla).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.15%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment confirms exploitation status as "none" (GitHub Advisory).
Users should update Qt to a version that includes the fix for this vulnerability — specifically, versions beyond 6.8.8 (in the 5.10.x–6.8.x branch) and beyond 6.11.1 (in the 6.9.x–6.11.x branch). The patch is available via the Qt project code review at https://codereview.qt-project.org/c/qt/qtdeclarative/+/754718. As a workaround, applications should validate and sanitize all SVG path input from untrusted sources before passing it to Context2D.path or PathSvg.path (GitHub Advisory, Red Hat Bugzilla).
Qt published an official security advisory on their blog at the time of disclosure. Red Hat tracked the issue via Bugzilla (Bug 2539304) and classified it as medium severity. No significant broader community or social media discussion has been observed beyond standard vulnerability aggregator coverage (Qt Security Advisory, Red Hat Bugzilla).
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bookworm
qtdeclarative-opensource-src
sid
qtdeclarative-opensource-src
trixie
qtdeclarative-opensource-src
devel
qt6-declarative
jammy
qt6-declarative
jammy (esm-apps)
qt6-declarative
noble
qt6-declarative
noble (esm-apps)
qt6-declarative
resolute
qt6-declarative
resolute (esm-apps)
qt6-declarative
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."