CVE-2026-95509 PUBLISHED

Out-of-bounds read vulnerability in string formatting impacts Qt for MCUs

Assigner: Qt
Reserved: 22.09.2026 Published: 29.09.2026 Updated: 29.09.2026

Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor qt
Product Qt for MCUs
Versions Default: unaffected
  • affected from 2.6.0 to 2.11.3 (excl.)
  • affected from 2.12.0 to 2.12.3 (excl.)

References

Problem Types

  • CWE-125 Out-of-bounds Read CWE
  • CWE-131 Incorrect Calculation of Buffer Size CWE

Impacts

  • CAPEC-540 Overread Buffers
  • CAPEC-47 Buffer Overflow via Parameter Expansion