CVE-2026-95509 Details
Description
Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.
A vulnerability allowing out-of-bounds reading has been identified in the String.arg() formatting function of Qt for MCUs. This issue arises when a Latin-1 optimized string with Latin-1 characters is processed, leading to incorrect formatting. The vulnerability is present in versions 2.6.0 through 2.11.2 and 2.12.0 through 2.12.2 of Qt for MCUs. The improper string handling can disrupt application performance and, in some cases, cause the application to crash unexpectedly.
Users can upgrade to Qt for MCUs version 2.11.3 or 2.12.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products#CVE-2026-95509: | TQtC |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| Qt | >= 2.2.0, <= 6.8.8 (semver) >= 6.9.0, <= 6.11.1 (semver) |
CPE
Remediation
| |
| Qt for MCUs | >= 2.6.0, <= 2.11.2 (semver) >= 2.12.0, <= 2.12.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | TQtC |
Volerion