CVE-2026-19248

NameCVE-2026-19248
DescriptionQDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148271, 1148272

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qt6-base (PTS)bookworm6.4.2+dfsg-10vulnerable
trixie6.8.2+dfsg-9+deb13u2vulnerable
forky, sid6.11.2+dfsg-5fixed
qtbase-opensource-src (PTS)bookworm5.15.8+dfsg-11+deb12u3vulnerable
trixie5.15.15+dfsg-6+deb13u1vulnerable
forky, sid5.15.19+dfsg-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qt6-basesource(unstable)6.11.2+dfsg-51148271
qtbase-opensource-srcsource(unstable)5.15.19+dfsg-51148272

Notes

[trixie] - qt6-base <no-dsa> (Minor issue)
[bookworm] - qt6-base <postponed> (Minor issue, DoS)
[trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
[bookworm] - qtbase-opensource-src <postponed> (Minor issue, DoS)
https://qt-project.atlassian.net/browse/QTBUG-147191
Fixed by: https://github.com/qt/qtbase/commit/474f268a8e04a4d2d66aa7e36b3b72cc1c1ef769 (v6.11.2)
Fixed by: https://github.com/qt/qtbase/commit/1303f05b33bb777626644729dd3b1330f60ecb7f (6.10)

Search for package or bug name: Reporting problems