VDB
GCVE-VVD-MAGEIA-2019-356
GCVE-VVD-MAGEIA-2019-356
Advisory Published
This update provides the 5.12.6 QT stack maintenance release and fixes
the following security issue:
An out-of-bounds memory access in the generateDirectionalRuns() function
in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows
attackers to cause a denial of service by crashing an application via a
text file containing many directional characters (CVE-2019-18281).
kwin and skrooge has been rebuilt to pick up proper dependencies on the
updated QT packages.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | qtremoteobjects5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtcharts5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtserialbus5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qttranslations5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | skrooge | 0 (affected), 2.19.1-2.mga7 (unaffected) | — |
| Mageia | qtgraphicaleffects5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtgamepad5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qttools5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtspeech5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtimageformats5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtquickcontrols5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtwebkit5 | 0 (affected), 5.212.0-1.alpha3.1.mga7 (unaffected) | — |
| Mageia | qt3d5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtwebview5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtvirtualkeyboard5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtlocation5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtx11extras5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtconnectivity5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtnetworkauth5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtdoc5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtdeclarative5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtwebengine5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtmultimedia5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtsensors5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtbase5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtwebglplugin5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtenginio5 | 0 (affected), 1.6.3-7.1.mga7 (unaffected) | — |
| Mageia | qtscxml5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtsvg5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtxmlpatterns5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtwebsockets5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtdatavis3d5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtpurchasing5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | pyside2 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtscript5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | kwin | 0 (affected), 5.15.4-1.1.mga7 (unaffected) | — |
| Mageia | shiboken2 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtwayland5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtserialport5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtwebchannel5 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | qtquickcontrols25 | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
| Mageia | pyside2-tools | 0 (affected), 5.12.6-1.mga7 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.