CVE-2025-23050: Low severity Qt QLowEnergyController vulnerability
Published Oct 31, 2025
·Updated
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
Affected Software
1 affected component
Qt QLowEnergyController<5.15.19, <6.5.9, <6.8.2
Event History
Oct 31, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-23050?
CVE-2025-23050 is classified as a critical vulnerability due to the potential for out-of-bounds reads or division by zero.
2
How do I fix CVE-2025-23050?
To fix CVE-2025-23050, upgrade to Qt versions 5.15.19, 6.5.9, or 6.8.2.
3
Which versions of QLowEnergyController are affected by CVE-2025-23050?
CVE-2025-23050 affects all versions of QLowEnergyController before 5.15.19, 6.5.9, and 6.8.2.
4
What risks does CVE-2025-23050 pose?
CVE-2025-23050 can lead to application crashes or exploitation due to mishandled Bluetooth ATT commands.
5
Is CVE-2025-23050 a local or remote vulnerability?
CVE-2025-23050 is primarily a remote vulnerability, as it involves Bluetooth communication that can be exploited from nearby devices.