First published: Fri Apr 11 2025(Updated: )
There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.0 are known to be unaffected, and the fix is in 6.8.4 and later.
Credit: a59d8014-47c4-4630-ab43-e1b13cbe58e3
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Base | >=6.8.0<6.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3512 has been rated as a critical severity vulnerability due to the potential for remote code execution.
To fix CVE-2025-3512, upgrade Qt to version 6.8.5 or later where the vulnerability has been patched.
CVE-2025-3512 affects Qt versions 6.8.0 to 6.8.4.
CVE-2025-3512 can be exploited by passing an incorrectly formatted markdown file to QTextMarkdownImporter, leading to a heap-based buffer overflow.
Yes, Qt versions prior to 6.8.0 and 6.6.0 are known to be unaffected by CVE-2025-3512.