CVE-2025-5683

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*

History

15 Oct 2025, 17:06

Type Values Removed Values Added
References () https://codereview.qt-project.org/c/qt/qtimageformats/+/644548 - () https://codereview.qt-project.org/c/qt/qtimageformats/+/644548 - Patch
References () https://issues.oss-fuzz.com/issues/415350704 - () https://issues.oss-fuzz.com/issues/415350704 - Issue Tracking, Patch
First Time Qt
Qt qt
CPE cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

05 Jun 2025, 20:12

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-05 06:15

Updated : 2025-10-15 17:06


NVD link : CVE-2025-5683

Mitre link : CVE-2025-5683

CVE.ORG link : CVE-2025-5683


JSON object : View

Products Affected

qt

  • qt
CWE
CWE-770

Allocation of Resources Without Limits or Throttling