Skip to main content
Vulnerability Database/CVE-2026-79616

CVE-2026-79616: Qt Quick Buffer Overflow Vulnerability

CVE-2026-79616 is a buffer overflow flaw in Qt Quick that occurs when parsing untrusted SVG path strings in Context2D.path and PathSvg.path. This post explains the technical details, affected versions, and mitigation steps.

Published:

CVE-2026-79616 Overview

CVE-2026-79616 is an out-of-bounds read vulnerability in Qt Quick's Context2D SVG path parser. The flaw affects the Context2D.path and PathSvg.path properties within the qtdeclarative module. When these properties process untrusted SVG path strings, the parser reads memory outside the intended buffer bounds. The issue is classified under [CWE-125: Out-of-bounds Read].

Exploitation requires local access, low privileges, and user interaction with a malicious SVG path input. The vulnerability can crash Qt Quick applications that render attacker-controlled path data. Impact is limited to availability; confidentiality and integrity are not affected according to the CVSS 4.0 metrics.

Critical Impact

Applications parsing untrusted SVG path strings through Qt Quick's Context2D or PathSvg can experience process crashes and denial of service.

Affected Products

  • Qt Framework - qtdeclarative module
  • Qt Quick Context2D path property
  • Qt Quick PathSvg path property

Discovery Timeline

  • 2026-09-23 - CVE-2026-79616 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-79616

Vulnerability Analysis

The vulnerability resides in the SVG path string parser used by Qt Quick's declarative graphics stack. Qt Quick exposes Context2D.path and PathSvg.path properties that accept SVG path syntax as string input. The parser walks the string character by character to build drawing commands.

When the parser encounters malformed or truncated SVG path data, it can advance its cursor past the end of the input buffer. The resulting out-of-bounds read accesses adjacent memory, which typically triggers a segmentation fault in the host process.

Applications embedding QML content that renders untrusted SVG path data are exposed. This includes desktop applications, kiosks, and embedded systems using Qt Quick for user interfaces.

Root Cause

The root cause is missing bounds validation in the SVG path tokenizer. The parser assumes well-formed input and does not consistently verify that the read pointer remains within the string's length before dereferencing. Specific malformed sequences allow the parser to read beyond the terminating position of the path string.

Attack Vector

An attacker supplies a crafted SVG path string to an application that assigns it to Context2D.path or PathSvg.path. Delivery requires local access and user interaction, such as opening a file or loading a document containing the malicious path. Successful triggering causes an out-of-bounds read that most often results in application termination.

The vulnerability mechanism involves the SVG path parser reading beyond allocated bounds. Refer to the Qt Project Code Review for the corrective patch and parser changes.

Detection Methods for CVE-2026-79616

Indicators of Compromise

  • Unexpected crashes or segmentation faults in Qt Quick applications after loading SVG or QML content.
  • Application logs showing errors originating from the QQuickContext2D or QQuickPathSvg classes.
  • Presence of untrusted QML or SVG assets in user-writable application data directories.

Detection Strategies

  • Monitor for repeated process crashes in binaries linked against QtQuick and QtDeclarative libraries.
  • Inspect input pipelines that feed SVG path strings into QML components for validation gaps.
  • Correlate crash dumps with stack frames in the SVG path parser to confirm exploitation attempts.

Monitoring Recommendations

  • Enable core dump collection on endpoints running Qt-based applications for post-crash forensic review.
  • Alert on abnormal termination rates for applications that render user-supplied graphical content.
  • Track file drops of .svg, .qml, and related asset formats in application working directories.

How to Mitigate CVE-2026-79616

Immediate Actions Required

  • Inventory applications built on Qt Quick that expose Context2D.path or PathSvg.path to untrusted input.
  • Apply the upstream qtdeclarative fix from the Qt Project Code Review once packaged in a Qt release.
  • Restrict which users can supply SVG path content to affected applications.

Patch Information

The fix is available through the upstream Qt Project change under review at qtdeclarative/+/754718. Rebuild affected applications against a Qt version that includes the parser bounds-check correction. Downstream distribution packages should be updated once the patched Qt release ships.

Workarounds

  • Validate SVG path strings against a strict allow-list before assigning them to Context2D.path or PathSvg.path.
  • Reject or sanitize path strings that contain unterminated commands, missing numeric operands, or excessive length.
  • Isolate rendering of untrusted SVG content in a sandboxed process to contain crashes.
bash
# Configuration example
# Verify the linked Qt Declarative version on a Linux host
ldd ./your-qt-app | grep -E 'Qt(Quick|Declarative)'
dpkg -l | grep qtdeclarative   # Debian/Ubuntu
rpm -qa | grep qt5-qtdeclarative # RHEL/Fedora

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.