An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matching routine reads past the end of the supplied buffer. In most cases this results in an incorrect text codec being selected; in the worst case, if the over-read reaches unmapped memory, the process crashes (denial of service). The over-read is bounded by the length of the longest codec-name candidate, and the out-of-bounds bytes are only compared internally against Qt's fixed list of codec names, so no data is disclosed to an attacker. Applications that do not pass non-NUL-terminated QByteArrays to QTextCodec::codecForName() are not exposed. The affected code resides in the Qt5Compat module from Qt 6.0.0 onward, and in Qt Core (qtbase) in Qt 4.x and Qt 5.x.
CVSS Details
- CVSS 4.0 Base Score: 6.3 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade qt5-qtbase-debuginfoUpgrade qt6-qt5compat-tests-debuginfoUpgrade qt6-qt5compat-develUpgrade qt5-qtbase-commonUpgrade qt6-qt5compat-examplesUpgrade qt5-qtbaseUpgrade qt5-qtbase-mysql-debuginfoUpgrade qt5-qtbase-gui-debuginfoUpgrade qt5-qtbase-private-develUpgrade qt5-qtbase-devel-debuginfoUpgrade qt5-qtbase-debugsourceUpgrade qt6-qt5compat-debuginfoUpgrade qt6-qt5compat-examples-debuginfoUpgrade qt6-qt5compat-debugsourceUpgrade qt5-qtbase-examplesUpgrade qt5-qtbase-tests-debuginfoUpgrade qt5-qtbase-odbcUpgrade qt5-qtbase-staticUpgrade qt5-qtbase-develUpgrade qt5-qtbase-postgresql-debuginfoNo solution existsUpgrade qt6-qt5compatUpgrade qt5-qtbase-guiUpgrade qt5-qtbase-odbc-debuginfoUpgrade qt5-qtbase-examples-debuginfoUpgrade qt5-qtbase-postgresqlUpgrade qt5-qtbase-mysql | Aug 26, 2026 | Jul 21, 2026 |
| Rocky_linux | — | Upgrade qt5-qtbase-examplesUpgrade qt5-qtbase-postgresql-debuginfoUpgrade qt5-qtbase-staticUpgrade qt5-qtbase-gui-debuginfoUpgrade qt6-qt5compat-examples-debuginfoUpgrade qt5-qtbase-postgresqlUpgrade qt5-qtbase-develUpgrade qt5-qtbase-odbc-debuginfoUpgrade qt6-qt5compatUpgrade qt5-qtbase-guiUpgrade qt5-qtbase-private-develUpgrade qt5-qtbase-mysqlUpgrade qt5-qtbase-debugsourceUpgrade qt6-qt5compat-develUpgrade qt6-qt5compat-debugsourceUpgrade qt6-qt5compat-examplesUpgrade qt5-qtbase-mysql-debuginfoUpgrade qt5-qtbase-examples-debuginfoUpgrade qt5-qtbase-odbcUpgrade qt5-qtbaseUpgrade qt6-qt5compat-debuginfoUpgrade qt5-qtbase-debuginfoUpgrade qt5-qtbase-devel-debuginfo | Sep 15, 2026 | Sep 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub