<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:36:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:9462 — Moderate: qt5-qtbase security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:9462</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: qt5-qtbase, AlmaLinux:9: qt5-qtbase-common, AlmaLinux:9: qt5-qtbase-devel, AlmaLinux:9: qt5-qtbase-examples, AlmaLinux:9: qt5-qtbase-gui, AlmaLinux:9: qt5-qtbase-mysql, AlmaLinux:9: qt5-qtbase-odbc, AlmaLinux:9: qt5-qtbase-postgresql, AlmaLinux:9: qt5-qtbase-private-devel, AlmaLinux:9: qt5-qtbase-static&lt;/p&gt;
&lt;p&gt;Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, xml, and network handling in Qt.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qt5: qt6: QtCore Assertion Failure Denial of Service (CVE-2025-5455)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: qt5-qtbase, AlmaLinux:9: qt5-qtbase-common, AlmaLinux:9: qt5-qtbase-devel, AlmaLinux:9: qt5-qtbase-examples, AlmaLinux:9: qt5-qtbase-gui, AlmaLinux:9: qt5-qtbase-mysql, AlmaLinux:9: qt5-qtbase-odbc, AlmaLinux:9: qt5-qtbase-postgresql, AlmaLinux:9: qt5-qtbase-private-devel, AlmaLinux:9: qt5-qtbase-static&lt;/p&gt;
&lt;p&gt;Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, xml, and network handling in Qt.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qt5: qt6: QtCore Assertion Failure Denial of Service (CVE-2025-5455)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:9462</guid>
    </item>
    <item>
      <title>bdu:2025-06498</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-06498</link>
      <description>bdu:2025-06498</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-06498</guid>
    </item>
    <item>
      <title>EUVD-2026-342265</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342265</link>
      <description>EUVD-2026-342265</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342265</guid>
    </item>
    <item>
      <title>fkie_cve-2025-5455</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-5455</link>
      <description>&lt;p&gt;An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.&lt;/p&gt;
&lt;p&gt;If the function was called with malformed data, for example, an URL that
contained a &amp;#34;charset&amp;#34; parameter that lacked a value (such as
&amp;#34;data:charset,&amp;#34;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).&lt;/p&gt;
&lt;p&gt;This impacts Qt up to 5.15.18, 6.0.0-&amp;gt;6.5.8, 6.6.0-&amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.&lt;/p&gt;
&lt;p&gt;If the function was called with malformed data, for example, an URL that
contained a &amp;#34;charset&amp;#34; parameter that lacked a value (such as
&amp;#34;data:charset,&amp;#34;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).&lt;/p&gt;
&lt;p&gt;This impacts Qt up to 5.15.18, 6.0.0-&amp;gt;6.5.8, 6.6.0-&amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-5455</guid>
    </item>
    <item>
      <title>GHSA-5cfg-qhv9-4842</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5cfg-qhv9-4842</link>
      <description>&lt;p&gt;An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.&lt;/p&gt;
&lt;p&gt;If the function was called with malformed data, for example, an URL that
contained a &amp;#34;charset&amp;#34; parameter that lacked a value (such as
&amp;#34;data:charset,&amp;#34;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).&lt;/p&gt;
&lt;p&gt;This impacts Qt up to 5.15.18, 6.0.0-&amp;gt;6.5.8, 6.6.0-&amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.&lt;/p&gt;
&lt;p&gt;If the function was called with malformed data, for example, an URL that
contained a &amp;#34;charset&amp;#34; parameter that lacked a value (such as
&amp;#34;data:charset,&amp;#34;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).&lt;/p&gt;
&lt;p&gt;This impacts Qt up to 5.15.18, 6.0.0-&amp;gt;6.5.8, 6.6.0-&amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5cfg-qhv9-4842</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-5455 — Possible denial of service when passing malformed data in a URL to qDecodeDataUrl</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-5455</link>
      <description>msrc_CVE-2025-5455</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-5455</guid>
    </item>
    <item>
      <title>OESA-2025-1654 — qt5-qtbase security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1654</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: qt5-qtbase, openEuler:22.03-LTS-SP4: qt5-qtbase, openEuler:24.03-LTS: qt5-qtbase, openEuler:24.03-LTS-SP1: qt5-qtbase, openEuler:20.03-LTS-SP4: qt5-qtbase&lt;/p&gt;
&lt;p&gt;Qt is a software toolkit for developing applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.&lt;/p&gt;
&lt;p&gt;If the function was called with malformed data, for example, an URL that
contained a &amp;amp;quot;charset&amp;amp;quot; parameter that lacked a value (such as
&amp;amp;quot;data:charset,&amp;amp;quot;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).&lt;/p&gt;
&lt;p&gt;This impacts Qt up to 5.15.18, 6.0.0-&amp;amp;gt;6.5.8, 6.6.0-&amp;amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.(CVE-2025-5455)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: qt5-qtbase, openEuler:22.03-LTS-SP4: qt5-qtbase, openEuler:24.03-LTS: qt5-qtbase, openEuler:24.03-LTS-SP1: qt5-qtbase, openEuler:20.03-LTS-SP4: qt5-qtbase&lt;/p&gt;
&lt;p&gt;Qt is a software toolkit for developing applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.&lt;/p&gt;
&lt;p&gt;If the function was called with malformed data, for example, an URL that
contained a &amp;amp;quot;charset&amp;amp;quot; parameter that lacked a value (such as
&amp;amp;quot;data:charset,&amp;amp;quot;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).&lt;/p&gt;
&lt;p&gt;This impacts Qt up to 5.15.18, 6.0.0-&amp;amp;gt;6.5.8, 6.6.0-&amp;amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.(CVE-2025-5455)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1654</guid>
    </item>
    <item>
      <title>RHSA-2025:11841 — Red Hat Security Advisory: qt5-qtbase security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11841</link>
      <description>&lt;p&gt;qt6-qtbase: qt5-qtbase: QtCore Assertion Failure Denial of Service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;qt6-qtbase: qt5-qtbase: QtCore Assertion Failure Denial of Service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11841</guid>
    </item>
    <item>
      <title>RHSA-2025:9462 — Red Hat Security Advisory: qt5-qtbase security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:9462</link>
      <description>&lt;p&gt;qt6-qtbase: qt5-qtbase: QtCore Assertion Failure Denial of Service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;qt6-qtbase: qt5-qtbase: QtCore Assertion Failure Denial of Service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:9462</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02968-1 — Security update for libqt4</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02968-1</link>
      <description>&lt;p&gt;Security update for libqt4&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libqt4&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02968-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-5455</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5455</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: qtbase-opensource-src, Ubuntu:16.04:LTS: qtbase-opensource-src-gles, Ubuntu:Pro:18.04:LTS: qtbase-opensource-src, Ubuntu:Pro:20.04:LTS: qtbase-opensource-src, Ubuntu:20.04:LTS: qtbase-opensource-src-gles, Ubuntu:22.04:LTS: qt6-base, Ubuntu:22.04:LTS: qtbase-opensource-src, Ubuntu:22.04:LTS: qtbase-opensource-src-gles, Ubuntu:24.04:LTS: qt6-base, Ubuntu:24.04:LTS: qtbase-opensource-src and 5 more&lt;/p&gt;
&lt;p&gt;An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a &amp;#34;charset&amp;#34; parameter that lacked a value (such as &amp;#34;data:charset,&amp;#34;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0-&amp;gt;6.5.8, 6.6.0-&amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: qtbase-opensource-src, Ubuntu:16.04:LTS: qtbase-opensource-src-gles, Ubuntu:Pro:18.04:LTS: qtbase-opensource-src, Ubuntu:Pro:20.04:LTS: qtbase-opensource-src, Ubuntu:20.04:LTS: qtbase-opensource-src-gles, Ubuntu:22.04:LTS: qt6-base, Ubuntu:22.04:LTS: qtbase-opensource-src, Ubuntu:22.04:LTS: qtbase-opensource-src-gles, Ubuntu:24.04:LTS: qt6-base, Ubuntu:24.04:LTS: qtbase-opensource-src and 5 more&lt;/p&gt;
&lt;p&gt;An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a &amp;#34;charset&amp;#34; parameter that lacked a value (such as &amp;#34;data:charset,&amp;#34;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0-&amp;gt;6.5.8, 6.6.0-&amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5455</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1220 — QT: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1220</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QT ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QT ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1220</guid>
    </item>
  </channel>
</rss>
