PT-2022-1644 · Qt Company+10 · Qt+10

Published

2022-02-16

·

Updated

2026-03-05

·

CVE-2022-25255

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qt versions 5.9.x through 5.15.x before 5.15.9 Qt versions 6.x before 6.2.4
Description The issue is related to the QProcess in Qt, which could execute a binary from the current working directory when not found in the PATH on Linux and UNIX systems. This could potentially allow a remote attacker to execute arbitrary code due to incorrect restriction of the directory path name with limited access.
Recommendations For Qt versions 5.9.x through 5.15.x before 5.15.9, update to version 5.15.9 or later to resolve the issue. For Qt versions 6.x before 6.2.4, update to version 6.2.4 or later to resolve the issue.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7482
ALSA-2022:8022
ALT-PU-2023-4298
ALT-PU-2023-4299
ALT-PU-2023-4300
ALT-PU-2023-4301
ALT-PU-2023-4302
ALT-PU-2023-4303
ALT-PU-2023-4304
ALT-PU-2023-4305
ALT-PU-2023-4306
ALT-PU-2023-4307
ALT-PU-2023-4308
ALT-PU-2023-4309
ALT-PU-2023-4310
ALT-PU-2023-4311
ALT-PU-2023-4312
ALT-PU-2023-4313
ALT-PU-2023-4314
ALT-PU-2023-4315
ALT-PU-2023-4316
ALT-PU-2023-4317
ALT-PU-2023-4318
ALT-PU-2023-4319
ALT-PU-2023-4320
ALT-PU-2023-4321
ALT-PU-2023-4322
ALT-PU-2023-4323
ALT-PU-2023-4324
ALT-PU-2023-4325
ALT-PU-2023-4326
ALT-PU-2023-4327
ALT-PU-2023-4328
ALT-PU-2023-4329
ALT-PU-2023-4330
ALT-PU-2023-4331
AZL-50050
BDU:2022-00893
CESA-2022_7482
CVE-2022-25255
INFSA-2022_7482
OESA-2022-1787
OESA-2022-1803
OPENSUSE-SU-2022:0841-1
OPENSUSE-SU-2022_0841-1
OPENSUSE-SU-2024:11879-1
OPENSUSE-SU-2024:11886-1
OPENSUSE-SU-2024:11974-1
RHSA-2022:7482
RHSA-2022:8022
RHSA-2022_7482
RHSA-2022_8022
RLSA-2022:7482
RLSA-2022:8022
SUSE-SU-2022:0841-1
USN-8076-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Qt
Red Hat
Rocky Linux
Suse
Ubuntu