CVE-2025-5683: Medium severity Qt QT vulnerability
When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.
This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.5.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.8.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.9.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5683?
CVE-2025-5683 is classified as a high severity vulnerability due to the potential crash it can cause in affected versions of QImage.
How do I fix CVE-2025-5683?
To fix CVE-2025-5683, upgrade to Qt versions 6.5.10, 6.8.5, or 6.9.1 or later.
Which versions of Qt are affected by CVE-2025-5683?
CVE-2025-5683 affects Qt versions from 6.3.0 to 6.5.9 and from 6.6.0 to 6.8.4.
What type of issue does CVE-2025-5683 represent?
CVE-2025-5683 represents a denial of service issue due to a crash when processing crafted ICNS image files.
Can CVE-2025-5683 be exploited remotely?
Yes, CVE-2025-5683 can potentially be exploited remotely if a user opens a malicious ICNS format image file.