logo

Qt Fixes Dual Critical Vulnerabilities (CVE-2025-10728 & CVE-2025-10729) in SVG Module

ID: 7ca58d5e-e428-5f21-be03-05b477abbb4d

STIX ID: report--7ca58d5e-e428-5f21-be03-05b477abbb4d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

The Qt Group published a security advisory for two critical Qt SVG module vulnerabilities—CVE-2025-10728 (infinite recursion via <pattern> elements leading to stack‑overflow DoS) and CVE-2025-10729 (use‑after‑free when parsing certain <pattern> nodes that may lead to memory corruption or possible remote code execution). Both affect Qt 6.7.0–6.8.4 and 6.9.0–6.9.2, carry a CVSS 9.4 rating, and Qt advises immediate upgrades to 6.9.3 or 6.8.5, not rendering untrusted SVGs, and reviewing third‑party dependencies; no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.