OESA-2025-2846

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-2846
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-2846.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2025-2846
Upstream
  • CVE-2025-12385
Published
2025-12-12T12:21:16Z
Modified
2025-12-12T12:44:52.165518Z
Summary
qt6-qtdeclarative security update
Details

.

Security Fix(es):

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive.

This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.(CVE-2025-12385)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP1 / qt6-qtdeclarative

Package

Name
qt6-qtdeclarative
Purl
pkg:rpm/openEuler/qt6-qtdeclarative&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.2-2.oe2403sp1

Ecosystem specific

{
    "src": [
        "qt6-qtdeclarative-6.5.2-2.oe2403sp1.src.rpm"
    ],
    "aarch64": [
        "qt6-qtdeclarative-6.5.2-2.oe2403sp1.aarch64.rpm",
        "qt6-qtdeclarative-debuginfo-6.5.2-2.oe2403sp1.aarch64.rpm",
        "qt6-qtdeclarative-debugsource-6.5.2-2.oe2403sp1.aarch64.rpm",
        "qt6-qtdeclarative-devel-6.5.2-2.oe2403sp1.aarch64.rpm",
        "qt6-qtdeclarative-examples-6.5.2-2.oe2403sp1.aarch64.rpm",
        "qt6-qtdeclarative-static-6.5.2-2.oe2403sp1.aarch64.rpm"
    ],
    "x86_64": [
        "qt6-qtdeclarative-6.5.2-2.oe2403sp1.x86_64.rpm",
        "qt6-qtdeclarative-debuginfo-6.5.2-2.oe2403sp1.x86_64.rpm",
        "qt6-qtdeclarative-debugsource-6.5.2-2.oe2403sp1.x86_64.rpm",
        "qt6-qtdeclarative-devel-6.5.2-2.oe2403sp1.x86_64.rpm",
        "qt6-qtdeclarative-examples-6.5.2-2.oe2403sp1.x86_64.rpm",
        "qt6-qtdeclarative-static-6.5.2-2.oe2403sp1.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2025-2846.json"