CVE-2025-5683: Medium severity Qt QT vulnerability
Published Jun 5, 2025
·Updated
When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.
Affected Software
4 affected components
Qt QT>=6.3.0<=6.5.9, >=6.6.0<=6.8.4
Qt QT>=6.3.0<6.5.10
Qt QT>=6.6.0<6.8.5
Qt QT>=6.9.0<6.9.1
Remediation
Patch Available
Event History
Jun 5, 2025
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
Description
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 30, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5683?
CVE-2025-5683 is classified as a high severity vulnerability due to the potential crash it can cause in affected versions of QImage.
2
How do I fix CVE-2025-5683?
To fix CVE-2025-5683, upgrade to Qt versions 6.5.10, 6.8.5, or 6.9.1 or later.
3
Which versions of Qt are affected by CVE-2025-5683?
CVE-2025-5683 affects Qt versions from 6.3.0 to 6.5.9 and from 6.6.0 to 6.8.4.
4
What type of issue does CVE-2025-5683 represent?
CVE-2025-5683 represents a denial of service issue due to a crash when processing crafted ICNS image files.
5
Can CVE-2025-5683 be exploited remotely?
Yes, CVE-2025-5683 can potentially be exploited remotely if a user opens a malicious ICNS format image file.