PT-2024-28743 · Qt Company+11 · Qt+11

Published

2024-06-25

·

Updated

2026-03-05

·

CVE-2024-39936

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Qt versions prior to 5.15.18 Qt versions 6.x prior to 6.2.13 Qt versions 6.3.x through 6.5.x prior to 6.5.7 Qt versions 6.6.x through 6.7.x prior to 6.7.3
Description An issue was discovered in HTTP2 in Qt where code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed.
Recommendations For Qt versions prior to 5.15.18, update to version 5.15.18 or later. For Qt versions 6.x prior to 6.2.13, update to version 6.2.13 or later. For Qt versions 6.3.x through 6.5.x prior to 6.5.7, update to version 6.5.7 or later. For Qt versions 6.6.x through 6.7.x prior to 6.7.3, update to version 6.7.3 or later.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

ALSA-2024:4617
ALSA-2024:4623
ALT-PU-2024-12677
ALT-PU-2024-14250
ALT-PU-2025-3157
ALT-PU-2025-3159
ALT-PU-2025-3160
ALT-PU-2025-3161
ALT-PU-2025-3162
ALT-PU-2025-3163
ALT-PU-2025-3164
ALT-PU-2025-3165
ALT-PU-2025-3166
ALT-PU-2025-3167
ALT-PU-2025-3168
ALT-PU-2025-3169
ALT-PU-2025-3170
ALT-PU-2025-3171
ALT-PU-2025-3172
ALT-PU-2025-3173
ALT-PU-2025-3174
ALT-PU-2025-3175
ALT-PU-2025-3176
ALT-PU-2025-3177
ALT-PU-2025-3178
ALT-PU-2025-3179
ALT-PU-2025-3180
ALT-PU-2025-3181
ALT-PU-2025-3182
ALT-PU-2025-3183
ALT-PU-2025-3184
ALT-PU-2025-3185
ALT-PU-2025-3186
ALT-PU-2025-3187
ALT-PU-2025-3188
ALT-PU-2025-6046
AZL-43192
BDU:2025-04695
CESA-2024_4617
CVE-2024-39936
DLA-4387-1
INFSA-2024_4617
INFSA-2024_4623
MGASA-2025-0046
OESA-2024-2572
OPENSUSE-SU-2024:14114-1
OPENSUSE-SU-2024:14215-1
RHSA-2024:4617
RHSA-2024:4621
RHSA-2024:4623
RHSA-2024:4638
RHSA-2024:4639
RHSA-2024:4644
RHSA-2024:4645
RHSA-2024:4646
RHSA-2024:4647
RHSA-2024_4617
RHSA-2024_4623
RLSA-2024:4617
RLSA-2024:4623
ROSA-SA-2025-2601
SUSE-SU-2024:2873-1
SUSE-SU-2024:2875-1
SUSE-SU-2024:2882-1
SUSE-SU-2024:2883-1
SUSE-SU-2024:2890-1
SUSE-SU-2024:2946-1
USN-8076-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Qt
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu