CVE-2024-30161: Use After Free
Published Mar 24, 2024
·Updated
In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)
Affected Software
4 affected components
Qt QT>=6.5.4<=6.5.5
Qt QT=6.5.4
Qt QT=6.5.5
Qt QT=6.6.2
Remediation
Patch Available
Event History
Mar 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30161?
The severity of CVE-2024-30161 is considered medium due to the potential for exploitation via a dangling pointer.
2
How do I fix CVE-2024-30161?
To fix CVE-2024-30161, upgrade Qt to version 6.5.6 or later, which addresses the vulnerability.
3
Which versions of Qt are affected by CVE-2024-30161?
Qt versions 6.5.4, 6.5.5, and 6.6.2 are affected by CVE-2024-30161.
4
What impact can CVE-2024-30161 have on applications?
CVE-2024-30161 can lead to unexpected behavior and potential data exposure in applications using Qt for WebAssembly.
5
Is there a workaround for CVE-2024-30161 if I cannot upgrade?
There are no known workarounds for CVE-2024-30161, so upgrading to a patched version is the recommended action.