Qt 5.0.0 through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke). Reference: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=35566 Upstream patches: https://github.com/qt/qtbase/commit/6b400e3147dcfd8cc3a393ace1bd118c93762e0c https://github.com/qt/qtbase/commit/1ca02cf2879a5e1511a2f2109f0925cf4c892862 https://github.com/qt/qtbase/commit/202143ba41f6ac574f1858214ed8bf4a38b73ccd
Created mingw-qt5-qtbase tracking bugs for this issue: Affects: fedora-all [bug 1994723] Created qt tracking bugs for this issue: Affects: fedora-all [bug 1994720] Created qt5 tracking bugs for this issue: Affects: fedora-all [bug 1994721] Created qt5-qtbase tracking bugs for this issue: Affects: fedora-all [bug 1994724] Created qt6 tracking bugs for this issue: Affects: fedora-all [bug 1994722] Created qt6-qtbase tracking bugs for this issue: Affects: fedora-all [bug 1994725]
NIST adjustment requested.
In reply to comment #2: > NIST adjustment requested. Please disregard.
Trackers have been created, analysis complete.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:1796 https://access.redhat.com/errata/RHSA-2022:1796