CVE-2025-6338: Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend
Published Oct 16, 2025
·Updated
There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.
Affected Software
1 affected component
Qt Qt Network>=5.15.0<=6.8.3, >6.9.0<=6.9.2
Event History
Oct 16, 2025
CVE Published
via MITRE·09:22 AM
Data Sourced
via MITRE·09:22 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-6338?
CVE-2025-6338 is classified as a Denial of Service vulnerability.
2
How do I fix CVE-2025-6338?
To fix CVE-2025-6338, update Qt Network to versions 6.9.2 or later or upgrade from versions 5.15.0 to 6.8.3.
3
What software is affected by CVE-2025-6338?
CVE-2025-6338 affects Qt Network versions 5.15.0 through 6.8.3 and versions 6.9.0 before 6.9.2.
4
What is the cause of CVE-2025-6338?
CVE-2025-6338 is caused by an incomplete cleanup in Qt Network's Schannel support on Windows.
5
What is the potential impact of CVE-2025-6338?
The potential impact of CVE-2025-6338 is a Denial of Service that may occur over a prolonged period.