]> dgit.raspbian.org Git - qtbase-opensource-src.git/commit
QTextCodec: avoid read-past-buffer in codecForName()
authorDebian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Mon, 21 Sep 2026 18:14:33 +0000 (21:14 +0300)
committerDmitry Shachnev <mitya57@debian.org>
Mon, 21 Sep 2026 18:14:33 +0000 (21:14 +0300)
commit678581c1cc55255c3884162fec88ff1ad61c5d5a
tree79641ec79407b844cfa1d1e517169a99816407b6
parent9a4ae359586f951dfd20f34de6651ba5a0e2aa78
QTextCodec: avoid read-past-buffer in codecForName()

Origin: upstream, https://code.qt.io/cgit/qt/qt5compat.git/commit/?id=894079b4932dc878
Last-Update: 2026-07-26

The old code passed a QByteArray to a function taking const char*,
invoking QByteArray::operator const char*() implicitly.

The callee expects the argument to be NUL-terminated, but if the
QByteArray was created fromRawData(), that is not guaranteed.

In newer Qt versions we have nullTerminated(), but this needs to be
picked further back, so use a std::string to do the null-termination.

Gbp-Pq: Name CVE-2026-9499.diff
src/corelib/codecs/qtextcodec.cpp