An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with . MGASA-2025-0212 - Updated qtbase6 & qtbase5 packages fix security vulnerability Publication date: 22 Jul 2025 URL: https://advisories.mageia.org/MGASA-2025-0212.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-5455 An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0-> 6.5.8, 6.6.0-> 6.8.3 and 6.9.0. References: - https://bugs.mageia.org/show_bug.cgi?id=34444 - - https://www.cve.org/CVERecord?id=CVE-2025-5455 SRPMS: - 9/core/qtbase6-6.4.1-5.2.mga9 - 9/core/qtbase5-5.15.7-6.2.mga9 . A critical alert for Mageia users warns of a denial of service vulnerability in qtbase5 and qtbase6 from improper handling of malformed data, urging prompt updates and audits. Mageia security advisory, qtbase6 update, denial of service, critical vulnerability. . Severity: Critical. LinuxSecurity.com Team
network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check. (CVE-2023-51714) A buffer overflow and application crash can occur via a crafted KTX image file. (CVE-2024-25580) Code to make security-relevant decisions about an established connection . MGASA-2025-0046 - Updated qtbase5 & qtbase6 packages fix security vulnerabilities Publication date: 09 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0046.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-51714, CVE-2024-25580, CVE-2024-39936 network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check. (CVE-2023-51714) A buffer overflow and application crash can occur via a crafted KTX image file. (CVE-2024-25580) Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed. (CVE-2024-39936) References: - https://bugs.mageia.org/show_bug.cgi?id=33159 - https://lwn.net/Articles/971686/ - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.