CVE-2021-38593: High severity Qt QT vulnerability
Published Aug 12, 2021
·Updated
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
Affected Software
4 affected components
Qt QT>=5.0.0<5.15.6
Qt QT>=6.0.0<=6.1.2
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Remediation
Patch Available
Event History
Aug 12, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 30, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38593?
The severity of CVE-2021-38593 is high with a severity value of 7.5.
2
Which software versions are affected by CVE-2021-38593?
Qt 5.x before 5.15.6 and 6.x through 6.1.2 are affected by CVE-2021-38593.
3
What is the vulnerability in CVE-2021-38593?
CVE-2021-38593 is an out-of-bounds write vulnerability in QOutlineMapper::convertPath.
4
How can I fix CVE-2021-38593?
To fix CVE-2021-38593, update Qt to version 5.15.6 or later for Qt 5.x, and update to version 6.1.2 or later for Qt 6.x.
5
Is Fedora affected by CVE-2021-38593?
Yes, Fedora versions 35 and 36 are affected by CVE-2021-38593.