PT-2025-16037 · Qt Company+1 · Qt+1

Oss-Fuzz

·

Published

2025-04-11

·

Updated

2025-12-16

·

CVE-2025-3512

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Name of the Vulnerable Software and Affected Versions: Qt versions 6.8.0 through 6.8.4
Description: There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.
Recommendations: For Qt versions 6.8.0 through 6.8.3, update to version 6.8.4 or later to resolve the issue. For Qt versions prior to 6.8.0, no action is required as these versions are not affected. As a temporary workaround, consider restricting the use of QTextMarkdownImporter until a patch is available.

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-16100
CVE-2025-3512

Affected Products

Qt
Red Os