CVE-2024-39936: High severity Qt QT vulnerability
An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39936?
The severity of CVE-2024-39936 is considered medium due to the potential for security-relevant decisions to be made prematurely.
How do I fix CVE-2024-39936?
To fix CVE-2024-39936, upgrade Qt to version 5.15.18 or later, or update to version 6.7.3 or newer.
What versions of Qt are affected by CVE-2024-39936?
CVE-2024-39936 affects Qt versions before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3.
What types of applications are impacted by CVE-2024-39936?
Applications using affected versions of the Qt framework that rely on HTTP2 functionality are impacted by CVE-2024-39936.
Does CVE-2024-39936 require immediate action?
Yes, organizations should address CVE-2024-39936 promptly to mitigate potential security risks associated with the vulnerability.