Fedora 42 update for LabPlot, dtk6core, dtk6gui, dtk6log, dtk6widget, fcitx5-qt, gammaray, kddockwidgets, kwin, libqtxdg, nheko, plasma-integration, python-pyqt6, python-pyside6, qt-creator, qt6, qt6-doc, qt6-qt3d, qt6-qt5compat, qt6-qtbase, qt6-qtcharts,



Risk Medium
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2025-5455
CVE-2025-5683
CWE-ID CWE-617
CWE-20
Exploitation vector Network
Public exploit N/A
Vulnerable software
Fedora
Operating systems & Components / Operating system

zeal
Operating systems & Components / Operating system package or component

qt6-qtwebview
Operating systems & Components / Operating system package or component

qt6-qtwebsockets
Operating systems & Components / Operating system package or component

qt6-qtwebengine
Operating systems & Components / Operating system package or component

qt6-qtwebchannel
Operating systems & Components / Operating system package or component

qt6-qtwayland
Operating systems & Components / Operating system package or component

qt6-qtvirtualkeyboard
Operating systems & Components / Operating system package or component

qt6-qttranslations
Operating systems & Components / Operating system package or component

qt6-qttools
Operating systems & Components / Operating system package or component

qt6-qtsvg
Operating systems & Components / Operating system package or component

qt6-qtspeech
Operating systems & Components / Operating system package or component

qt6-qtshadertools
Operating systems & Components / Operating system package or component

qt6-qtserialport
Operating systems & Components / Operating system package or component

qt6-qtserialbus
Operating systems & Components / Operating system package or component

qt6-qtsensors
Operating systems & Components / Operating system package or component

qt6-qtscxml
Operating systems & Components / Operating system package or component

qt6-qtremoteobjects
Operating systems & Components / Operating system package or component

qt6-qtquicktimeline
Operating systems & Components / Operating system package or component

qt6-qtquick3dphysics
Operating systems & Components / Operating system package or component

qt6-qtquick3d
Operating systems & Components / Operating system package or component

qt6-qtpositioning
Operating systems & Components / Operating system package or component

qt6-qtopcua
Operating systems & Components / Operating system package or component

qt6-qtnetworkauth
Operating systems & Components / Operating system package or component

qt6-qtmultimedia
Operating systems & Components / Operating system package or component

qt6-qtmqtt
Operating systems & Components / Operating system package or component

qt6-qtlottie
Operating systems & Components / Operating system package or component

qt6-qtlocation
Operating systems & Components / Operating system package or component

qt6-qtlanguageserver
Operating systems & Components / Operating system package or component

qt6-qtimageformats
Operating systems & Components / Operating system package or component

qt6-qthttpserver
Operating systems & Components / Operating system package or component

qt6-qtgrpc
Operating systems & Components / Operating system package or component

qt6-qtgraphs
Operating systems & Components / Operating system package or component

qt6-qtdeclarative
Operating systems & Components / Operating system package or component

qt6-qtdatavis3d
Operating systems & Components / Operating system package or component

qt6-qtconnectivity
Operating systems & Components / Operating system package or component

qt6-qtcoap
Operating systems & Components / Operating system package or component

qt6-qtcharts
Operating systems & Components / Operating system package or component

qt6-qtbase
Operating systems & Components / Operating system package or component

qt6-qt5compat
Operating systems & Components / Operating system package or component

qt6-qt3d
Operating systems & Components / Operating system package or component

qt6-doc
Operating systems & Components / Operating system package or component

qt6
Operating systems & Components / Operating system package or component

qt-creator
Operating systems & Components / Operating system package or component

python-pyside6
Operating systems & Components / Operating system package or component

python-pyqt6
Operating systems & Components / Operating system package or component

plasma-integration
Operating systems & Components / Operating system package or component

nheko
Operating systems & Components / Operating system package or component

libqtxdg
Operating systems & Components / Operating system package or component

kwin
Operating systems & Components / Operating system package or component

kddockwidgets
Operating systems & Components / Operating system package or component

gammaray
Operating systems & Components / Operating system package or component

fcitx5-qt
Operating systems & Components / Operating system package or component

dtk6widget
Operating systems & Components / Operating system package or component

dtk6log
Operating systems & Components / Operating system package or component

dtk6gui
Operating systems & Components / Operating system package or component

dtk6core
Operating systems & Components / Operating system package or component

LabPlot
Operating systems & Components / Operating system package or component

Vendor Fedoraproject

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Reachable assertion

EUVDB-ID: #VU112077

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2025-5455

CWE-ID: CWE-617 - Reachable Assertion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion within the qDecodeDataUrl() function in QtCore. A remote attacker can pass a specially crafted data, such as URL with a "charset" parameter but without a value, and crash the application. 

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Fedora: 42

zeal: before 0.7.2-9.fc42

qt6-qtwebview: before 6.9.1-1.fc42

qt6-qtwebsockets: before 6.9.1-1.fc42

qt6-qtwebengine: before 6.9.1-1.fc42

qt6-qtwebchannel: before 6.9.1-1.fc42

qt6-qtwayland: before 6.9.1-1.fc42

qt6-qtvirtualkeyboard: before 6.9.1-1.fc42

qt6-qttranslations: before 6.9.1-1.fc42

qt6-qttools: before 6.9.1-1.fc42

qt6-qtsvg: before 6.9.1-1.fc42

qt6-qtspeech: before 6.9.1-1.fc42

qt6-qtshadertools: before 6.9.1-1.fc42

qt6-qtserialport: before 6.9.1-1.fc42

qt6-qtserialbus: before 6.9.1-1.fc42

qt6-qtsensors: before 6.9.1-1.fc42

qt6-qtscxml: before 6.9.1-1.fc42

qt6-qtremoteobjects: before 6.9.1-1.fc42

qt6-qtquicktimeline: before 6.9.1-1.fc42

qt6-qtquick3dphysics: before 6.9.1-1.fc42

qt6-qtquick3d: before 6.9.1-1.fc42

qt6-qtpositioning: before 6.9.1-1.fc42

qt6-qtopcua: before 6.9.1-1.fc42

qt6-qtnetworkauth: before 6.9.1-1.fc42

qt6-qtmultimedia: before 6.9.1-1.fc42

qt6-qtmqtt: before 6.9.1-1.fc42

qt6-qtlottie: before 6.9.1-1.fc42

qt6-qtlocation: before 6.9.1-1.fc42

qt6-qtlanguageserver: before 6.9.1-1.fc42

qt6-qtimageformats: before 6.9.1-1.fc42

qt6-qthttpserver: before 6.9.1-1.fc42

qt6-qtgrpc: before 6.9.1-1.fc42

qt6-qtgraphs: before 6.9.1-1.fc42

qt6-qtdeclarative: before 6.9.1-1.fc42

qt6-qtdatavis3d: before 6.9.1-1.fc42

qt6-qtconnectivity: before 6.9.1-1.fc42

qt6-qtcoap: before 6.9.1-1.fc42

qt6-qtcharts: before 6.9.1-1.fc42

qt6-qtbase: before 6.9.1-1.fc42

qt6-qt5compat: before 6.9.1-1.fc42

qt6-qt3d: before 6.9.1-1.fc42

qt6-doc: before 6.9.1-1.fc42

qt6: before 6.9.1-1.fc42

qt-creator: before 16.0.1-2.fc42

python-pyside6: before 6.9.1-1.fc42

python-pyqt6: before 6.9.0-3.fc42

plasma-integration: before 6.3.5-3.fc42

nheko: before 0.12.0-15.fc42

libqtxdg: before 4.1.0-6.fc42

kwin: before 6.3.5-3.fc42

kddockwidgets: before 1.7.0-23.fc42

gammaray: before 3.1.0-11.fc42

fcitx5-qt: before 5.1.9-7.fc42

dtk6widget: before 6.0.27-5.fc42

dtk6log: before 0.0.2-7.fc42

dtk6gui: before 6.0.27-6.fc42

dtk6core: before 6.0.27-5.fc42

LabPlot: before 2.12.0-3.fc42

CPE2.3 External links

https://bodhi.fedoraproject.org/updates/FEDORA-2025-c546fd3f09


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Input validation error

EUVDB-ID: #VU112078

Risk: Medium

CVSSv4.0: 4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2025-5683

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in QImage when parsing an ICNS format image file. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Fedora: 42

zeal: before 0.7.2-9.fc42

qt6-qtwebview: before 6.9.1-1.fc42

qt6-qtwebsockets: before 6.9.1-1.fc42

qt6-qtwebengine: before 6.9.1-1.fc42

qt6-qtwebchannel: before 6.9.1-1.fc42

qt6-qtwayland: before 6.9.1-1.fc42

qt6-qtvirtualkeyboard: before 6.9.1-1.fc42

qt6-qttranslations: before 6.9.1-1.fc42

qt6-qttools: before 6.9.1-1.fc42

qt6-qtsvg: before 6.9.1-1.fc42

qt6-qtspeech: before 6.9.1-1.fc42

qt6-qtshadertools: before 6.9.1-1.fc42

qt6-qtserialport: before 6.9.1-1.fc42

qt6-qtserialbus: before 6.9.1-1.fc42

qt6-qtsensors: before 6.9.1-1.fc42

qt6-qtscxml: before 6.9.1-1.fc42

qt6-qtremoteobjects: before 6.9.1-1.fc42

qt6-qtquicktimeline: before 6.9.1-1.fc42

qt6-qtquick3dphysics: before 6.9.1-1.fc42

qt6-qtquick3d: before 6.9.1-1.fc42

qt6-qtpositioning: before 6.9.1-1.fc42

qt6-qtopcua: before 6.9.1-1.fc42

qt6-qtnetworkauth: before 6.9.1-1.fc42

qt6-qtmultimedia: before 6.9.1-1.fc42

qt6-qtmqtt: before 6.9.1-1.fc42

qt6-qtlottie: before 6.9.1-1.fc42

qt6-qtlocation: before 6.9.1-1.fc42

qt6-qtlanguageserver: before 6.9.1-1.fc42

qt6-qtimageformats: before 6.9.1-1.fc42

qt6-qthttpserver: before 6.9.1-1.fc42

qt6-qtgrpc: before 6.9.1-1.fc42

qt6-qtgraphs: before 6.9.1-1.fc42

qt6-qtdeclarative: before 6.9.1-1.fc42

qt6-qtdatavis3d: before 6.9.1-1.fc42

qt6-qtconnectivity: before 6.9.1-1.fc42

qt6-qtcoap: before 6.9.1-1.fc42

qt6-qtcharts: before 6.9.1-1.fc42

qt6-qtbase: before 6.9.1-1.fc42

qt6-qt5compat: before 6.9.1-1.fc42

qt6-qt3d: before 6.9.1-1.fc42

qt6-doc: before 6.9.1-1.fc42

qt6: before 6.9.1-1.fc42

qt-creator: before 16.0.1-2.fc42

python-pyside6: before 6.9.1-1.fc42

python-pyqt6: before 6.9.0-3.fc42

plasma-integration: before 6.3.5-3.fc42

nheko: before 0.12.0-15.fc42

libqtxdg: before 4.1.0-6.fc42

kwin: before 6.3.5-3.fc42

kddockwidgets: before 1.7.0-23.fc42

gammaray: before 3.1.0-11.fc42

fcitx5-qt: before 5.1.9-7.fc42

dtk6widget: before 6.0.27-5.fc42

dtk6log: before 0.0.2-7.fc42

dtk6gui: before 6.0.27-6.fc42

dtk6core: before 6.0.27-5.fc42

LabPlot: before 2.12.0-3.fc42

CPE2.3 External links

https://bodhi.fedoraproject.org/updates/FEDORA-2025-c546fd3f09


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###