Skip to main content

CVE-2025-5992: CWE-20 Improper Input Validation in The Qt Company Qt

Low
VulnerabilityCVE-2025-5992cvecve-2025-5992cwe-20
Published: Fri Jul 11 2025 (07/11/2025, 06:45:15 UTC)
Source: CVE Database V5
Vendor/Project: The Qt Company
Product: Qt

Description

When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to QColorSpace::fromICCProfile.This issue affects Qt from 6.6.0 through 6.8.3, from 6.9.0 through 6.9.1. This is fixed in 6.8.4 and 6.9.2.

Technical Details

Data Version
5.1
Assigner Short Name
TQtC
Date Reserved
2025-06-11T06:08:27.335Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6870b6b3a83201eaacacdbda

Added to database: 7/11/2025, 7:01:07 AM

Last updated: 7/11/2025, 7:01:07 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats