Qt Fixes Dual Critical Vulnerabilities (CVE-2025-10728 & CVE-2025-10729) in SVG Module
ID: 7ca58d5e-e428-5f21-be03-05b477abbb4d
STIX ID: report--7ca58d5e-e428-5f21-be03-05b477abbb4d
Feed Name: securityonline.info
The Qt Group published a security advisory for two critical Qt SVG module vulnerabilities—CVE-2025-10728 (infinite recursion via <pattern> elements leading to stack‑overflow DoS) and CVE-2025-10729 (use‑after‑free when parsing certain <pattern> nodes that may lead to memory corruption or possible remote code execution). Both affect Qt 6.7.0–6.8.4 and 6.9.0–6.9.2, carry a CVSS 9.4 rating, and Qt advises immediate upgrades to 6.9.3 or 6.8.5, not rendering untrusted SVGs, and reviewing third‑party dependencies; no active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
