Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 528
Alerts This Week
Warning Icon 1 528

Ubuntu 22.04 LTS: Qt Critical Denial of Service, Info Leak USN-7780-1

ubuntu
Calendar Grey September 29, 2025
Scroller Ubuntu
Multiple security issues in Qt require urgent updates. Address risks like denial of service and information leaks.
Several security issues were fixed in Qt.

Summary

Several security issues were fixed in Qt.

Software Description:

- qtbase-opensource-src: Qt 5 libraries

Details:

It was discovered that Qt did not correctly handle certain inputs when

using the SQL ODBC driver plugin. An attacker could possibly use this issue

to cause a denial of service. (CVE-2023-24607)

It was discovered that Qt did not correctly parse certain strict-transport-

security headers. An attacker could possibly use this issue to leak

sensitive information. This issue only affected Ubuntu 20.04 LTS and Ubuntu

22.04 LTS. (CVE-2023-32762)

It was discovered that Qt did not correctly handle certain inputs from DNS

servers. A remote attacker could possibly use this issue to execute

arbitrary code or cause a denial of service. (CVE-2023-33285)

It was discovered that Qt did not correctly validate certain CA

certificates for TLS. An attacker could possibly use this issue to gain

access to unauthorized resources. (CVE-2023-34410)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
  libqt5core5a                    5.15.3+dfsg-2ubuntu0.2+esm1
                                  Available with Ubuntu Pro
  libqt5gui5                      5.15.3+dfsg-2ubuntu0.2+esm1
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  libqt5core5a                    5.12.8+dfsg-0ubuntu2.1+esm1
                                  Available with Ubuntu Pro
  libqt5gui5                      5.12.8+dfsg-0ubuntu2.1+esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  libqt5core5a                    5.9.5+dfsg-0ubuntu2.6+esm1
                                  Available with Ubuntu Pro
  libqt5gui5                      5.9.5+dfsg-0ubuntu2.6+esm1
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  libqt5core5a                    5.5.1+dfsg-16ubuntu7.7+esm1
                                  Available with Ubuntu Pro
  libqt5gui5                      5.5.1+dfsg-16ubuntu7.7+esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7780-1

CVE-2023-24607, CVE-2023-32762, CVE-2023-33285, CVE-2023-34410

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7780-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.