CVE-2025-5455

Publication date 2 June 2025

Last updated 2 June 2025


Ubuntu priority

Description

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

Status

Package Ubuntu Release Status
qt6-base 25.10 questing
Needs evaluation
25.04 plucky
Needs evaluation
24.10 oracular Ignored end of life, was needs-triage
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
20.04 LTS focal Not in release
qtbase-opensource-src 25.10 questing
Not affected
25.04 plucky Ignored changes too intrusive
24.10 oracular Ignored end of life, was needs-triage
24.04 LTS noble Ignored changes too intrusive
22.04 LTS jammy Ignored changes too intrusive
20.04 LTS focal Ignored changes too intrusive
18.04 LTS bionic Ignored changes too intrusive
16.04 LTS xenial Ignored changes too intrusive
qtbase-opensource-src-gles 25.10 questing
Needs evaluation
25.04 plucky
Needs evaluation
24.10 oracular Ignored end of life, was needs-triage
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation
16.04 LTS xenial
Needs evaluation