CVE-2018-15518: Double Free
A possible double free and heap corruption was found in QXmlStream.
Upstream patch:
https://codereview.qt-project.org/#/c/236691/
Other sources
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-15518?
CVE-2018-15518 is a vulnerability in the QXmlStream component of Qt 5.x before 5.11.3 that allows for a double-free or corruption during parsing of a specially crafted illegal XML document.
What is the severity of CVE-2018-15518?
CVE-2018-15518 has a severity rating of 8.8 (high).
Which versions of Qt are affected by CVE-2018-15518?
Qt versions 5.9.5 and 5.11.1 are affected by CVE-2018-15518.
How can I fix CVE-2018-15518?
To fix CVE-2018-15518, it is recommended to update Qt to version 5.11.3 or later.
Where can I find more information about CVE-2018-15518?
More information about CVE-2018-15518 can be found in the references provided: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2018-12/msg00066.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00057.html), [Reference 3](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00071.html).