Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Security advisory: CVE-2026-78253 Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt

Дата публикации: 23-09-2026 11:21:28

A denial-of-service (stack-exhaustion) vulnerability in the QXmlStreamReader::readElementText() function of the XML parsing functionality of Qt Core has been discovered and has been assigned the CVE id CVE-2026-78253. 

Основное содержимое страницы с новостью.

A denial-of-service (stack-exhaustion) vulnerability in the QXmlStreamReader::readElementText() function of the XML parsing functionality of Qt Core has been discovered and has been assigned the CVE id CVE-2026-78253. 

Affected versions: From Qt 5.0 to Qt 6.8.8, from Qt 6.9.0 to Qt 6.11.1

Impact: When a deeply nested XML document is passed to QXmlStreamReader::readElementText(), the recursive parsing can exhaust the call stack and crash the application, even for moderately sized inputs. Such documents may originate from untrusted sources, for example via XMLHttpRequest in QML or data fetched with QNetworkAccessManager. 

CVSS 4.0 Score: 2.3 / Low 

Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:N/R:U/RE:L/U:Green

Mitigation: Count and restrict the nesting level of XML documents before parsing them with QXmlStreamReader. 

Solution: Apply the following patch or update to Qt 6.8.9, Qt 6.11.2, or later. 

Related Articles

Security advisory: CVE-2026-79616 Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick

Security advisory: CVE-2026-79616 Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick

Out-of-bounds read vulnerability in the Qt Quick Context2D.path and..

Read Article

Security advisory: CVE-2026-76151 out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)

Security advisory: CVE-2026-76151 out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module)

An out-of-bounds read (buffer over-read) vulnerability in the HTTP..

Read Article

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Security advisory: CVE-2026-79616 Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick09.2123-09-2026
2Oracle Security Alert Advisory - CVE-2026-35273 01011-06-2026
3SUSE 2026-2731-1 editorconfig-core-c Moderate Stack Overflow Threat0503-07-2026
4SUSE jq Moderate Policy Bypass and Stack Overflow Fix 2026-23735-101021-09-2026
5SUSE glibc Moderate Buffer Overflow Vulnerability 2026-23738-101021-09-2026
6KDE Plasma Affected By Arbitrary Code Execution To Break Sandboxes With "Open New Window"-2702-07-2026
7CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path07.5420-05-2026
8Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay01528-07-2026
9Rust Issues Warning Over Key Developers Being Targeted For Compromise06.417-09-2026
10Attackers Exploit N-able Patch Bypass Flaw on RMM Servers011.2303-08-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 14.36. Источник: www.qt.io.