| Name | CVE-2026-19248 |
| Description | QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1148271, 1148272 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| qt6-base (PTS) | bookworm | 6.4.2+dfsg-10 | vulnerable |
| trixie | 6.8.2+dfsg-9+deb13u2 | vulnerable |
| forky, sid | 6.11.2+dfsg-5 | fixed |
| qtbase-opensource-src (PTS) | bookworm | 5.15.8+dfsg-11+deb12u3 | vulnerable |
| trixie | 5.15.15+dfsg-6+deb13u1 | vulnerable |
| forky, sid | 5.15.19+dfsg-5 | fixed |
The information below is based on the following data on fixed versions.
Notes
[trixie] - qt6-base <no-dsa> (Minor issue)
[bookworm] - qt6-base <postponed> (Minor issue, DoS)
[trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
[bookworm] - qtbase-opensource-src <postponed> (Minor issue, DoS)
https://qt-project.atlassian.net/browse/QTBUG-147191
Fixed by: https://github.com/qt/qtbase/commit/474f268a8e04a4d2d66aa7e36b3b72cc1c1ef769 (v6.11.2)
Fixed by: https://github.com/qt/qtbase/commit/1303f05b33bb777626644729dd3b1330f60ecb7f (6.10)