Denial of Service Vulnerability in Qt Framework Affecting Multiple Versions
CVE-2025-5992

2.3LOW

Key Information:

Status
Vendor
CVE Published:
11 July 2025

What is CVE-2025-5992?

A vulnerability exists within the Qt framework that may lead to a denial of service. This occurs when unexpected values are passed to the QColorTransferGenericFunction, particularly when a specially crafted ICC profile is provided to QColorSpace::fromICCProfile. Users running affected versions of the Qt framework (from 6.6.0 to 6.8.3 and 6.9.0 to 6.9.1) are at risk. The issue has been addressed in version 6.8.4 and 6.9.2, highlighting the importance of keeping the framework up to date to mitigate potential attacks.

Affected Version(s)

Qt 6.6.0 <= 6.8.3

Qt 6.9.0 <= 6.9.1

Qt 6.0.0 < 6.6.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

OSS-Fuzz
.
CVE-2025-5992 : Denial of Service Vulnerability in Qt Framework Affecting Multiple Versions