PT-2024-10473 · Qt Company+2 · Qt+2
Published
2024-03-23
·
Updated
2025-04-18
·
CVE-2024-30161
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Qt versions 6.5.4 through 6.5.5
Qt version 6.6.2
Description
The issue is related to the use of memory after it has been freed, which can lead to information disclosure. This can be exploited by a remote attacker to cause a denial of service. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For Qt versions 6.5.4 through 6.5.5, update to version 6.5.6 or later to resolve the issue.
For Qt version 6.6.2, update to version 6.6.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the QNetworkReply header data in the wasm component until a patch is available.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qt
Red Os
Suse