This update for libqt5-qtbase fixes the following issues:
Security issues fixed:
* CVE-2025-5455: processing of malformed data in `qDecodeDataUrl()` can
trigger assertion and cause a crash (bsc#1243958).
* CVE-2025-30348: complex algorithm used in `encodeText` in QDom when
processing XML data can cause low performance (bsc#1239896).
Other issues fixed:
* Initialize a member variable in `QObjectPrivate::Signal` that was
uninitialized under some circumstances.
* Fix a crash when parsing a particular glyph in a particular font.
* Avoid repeatedly registering xsettings callbacks when switching cursor
themes.
* Check validity of RandR output info before using it.
* Fix reparenting a window so it takes effect even if there are no other state
changes to the window.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3723=1
* Desktop Applications Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-3723=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3723=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2025-3723=1 openSUSE-SLE-15.6-2025-3723=1
* Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3723=1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libQt5Sql5-sqlite-5.15.12+kde151-150600.3.9.1
* libQt5Widgets-devel-5.15.12+kde151-150600.3.9.1
* libQt5Sql5-debuginfo-5.15.12+kde151-150600.3.9.1
* libQt5DBus-devel-debuginfo-5.15.12+kde151-150600.3.9.1
* libQt5OpenGL5-debuginfo-5.15.12+kde151-150600.3.9.1
* libQt5Network5-debuginfo-5.15.12+kde151-150600.3.9.1
* libQt5Network5-5.15.12+kde151-150600.3.9.1
* libQt5PlatformHeaders-devel-5.15.12+kde151-150600.3.9.1
* libQt5PrintSupport5-debuginfo-5.15.12+kde151-150600.3.9.1
* libQt5Concurrent5-debuginfo-5.15.12+kde151-150600.3.9.1
* libQt5Gui5-5.15.12+kde151-150600.3.9.1
* libQt5Network-devel-5.15.12+kde151-150600.3.9.1
* libQt5Gui-devel-5.15.12+kde151-150600.3.9.1
* libQt5Sql5-5.15.12+kde151-150600.3.9.1
* libQt5Widgets5-5.15.12+kde151-150600.3.9.1
* libQt5PlatformSupport-devel-static-5.15.12+kde151-150600.3.9.1
* libQt5PrintSupport-devel-5.15.12+kde151-150600.3.9.1
* libQt5Test-devel-5.15.12+kde151-150600.3.9.1
*...
Read the Full Advisory* bsc#1239896
* bsc#1243958
## References:
* https://www.suse.com/security/cve/CVE-2025-30348.html
* https://www.suse.com/security/cve/CVE-2025-5455.html
* https://bugzilla.suse.com/show_bug.cgi?id=1239896
* https://bugzilla.suse.com/show_bug.cgi?id=1243958
Get the latest Linux and open source security news straight to your inbox.