CVE-2024-25580: Buffer Overflow
An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17 6.x before 6.2.12 6.3.x through 6.5.x before 6.5.5 and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.
Other sources
An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.
— MITRE
CVE-2024-25580: A recently reported potential buffer overflow issue in Qt’s KTX’s image handling has been assigned the CVE id CVE-2024-25580. An issue was discovered in Qt from 5.12.0 through 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. With a specifically crafted KTX image file it is possible that the application reading it could cause an overflow and subsequently a crash.
Fixed qtbase-6.6.2 is already in-tree (pending stable), qtgui will need: https://download.qt.io/officialreleases/qt/5.15/CVE-2024-25580-qtbase-5.15.diff
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25580?
CVE-2024-25580 has a high severity rating due to the potential for a buffer overflow leading to application crashes.
How do I fix CVE-2024-25580?
To fix CVE-2024-25580, upgrade to the latest version of Qt, specifically version 6.6.2 or higher.
What are the impacted versions for CVE-2024-25580?
The impacted versions for CVE-2024-25580 include Qt versions before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2.
Can CVE-2024-25580 be exploited remotely?
Yes, CVE-2024-25580 can be exploited through a crafted KTX image file which may allow attackers to execute a buffer overflow.
What types of applications are affected by CVE-2024-25580?
Applications using vulnerable versions of the Qt framework for processing KTX image files are affected by CVE-2024-25580.