CVE-2025-5683

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*

History

15 Oct 2025, 17:06

Type Values Removed Values Added
First Time Qt
Qt qt
CPE cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://codereview.qt-project.org/c/qt/qtimageformats/+/644548 - () https://codereview.qt-project.org/c/qt/qtimageformats/+/644548 - Patch
References () https://issues.oss-fuzz.com/issues/415350704 - () https://issues.oss-fuzz.com/issues/415350704 - Issue Tracking, Patch

05 Jun 2025, 19:15

Type Values Removed Values Added
CWE CWE-770
Summary
  • (es) Al cargar un archivo de imagen con formato ICNS especialmente manipulado en QImage, se produce un bloqueo. Este problema afecta a Qt desde la versión 6.3.0 hasta la 6.5.9, desde la 6.6.0 hasta la 6.8.4 y la 6.9.0. Se ha corregido en las versiones 6.5.10, 6.8.5 y 6.9.1.

05 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-05 06:15

Updated : 2025-10-15 17:06


NVD link : CVE-2025-5683

Mitre link : CVE-2025-5683

CVE.ORG link : CVE-2025-5683


JSON object : View

Products Affected

qt

  • qt
CWE
CWE-770

Allocation of Resources Without Limits or Throttling