Use-after-free in Qt - CVE-2025-10729
Published: October 6, 2025
Vulnerability details
The vulnerability allows a remote attacker to potentially execute arbitrary code.
The vulnerability exists due to a use-after-free error when parsing .SVG images with "<pattern>" element. A remote attacker can pass a specially crafted .SVG file to the application and perform a denial of service attack or potentially execute arbitrary code.
Affected software
Gentoo Linux
Fedora
openEuler
dtk6log
zeal
nheko
kddockwidgets
LabPlot
gammaray
fcitx5-qt
qt5-qtsvg-debugsource
qt5-qtsvg-devel
qt5-qtsvg-debuginfo
qt5-qtsvg
qt5-qtsvg-examples
mingw-qt5-qtsvg
dtk6widget
dtk6core
dtk6gui
qt6-qtsvg (Red Hat package)
mingw-qt6-qtsvg
python-pyqt6
dev-qt/qtsvg
mingw-qt6-qtscxml
mingw-qt6-qtmultimedia
mingw-qt6-qtsensors
mingw-qt6-qtserialport
mingw-qt6-qtshadertools
mingw-qt6-qttools
mingw-qt6-qttranslations
qt6-qtbase
mingw-qt6-qtwebchannel
qt6-qtwebview
qt6-qtwebsockets
qt6-qtcharts
mingw-qt6-qtpositioning
qt6-qtwebengine
mingw-qt6-qtlocation
mingw-qt6-qtimageformats
mingw-qt6-qtdeclarative
mingw-qt6-qtcharts
mingw-qt6-qtbase
mingw-qt6-qtactiveqt
mingw-qt6-qt5compat
mingw-qt6-qt3d
qt6-qt5compat
qt6-qt3d
qt6
mingw-qt6-qtwebsockets
qt6-qtquick3d
qt6-qtcoap
qt6-qtconnectivity
qt6-qtdatavis3d
qt6-qtdeclarative
qt6-qthttpserver
qt6-qtimageformats
qt6-qtlanguageserver
qt6-qtlocation
qt6-qtlottie
qt6-qtmqtt
qt6-qtmultimedia
qt6-qtnetworkauth
qt6-qtopcua
qt6-qtpositioning
qt6-qtwebchannel
qt6-qtquick3dphysics
qt6-qtquicktimeline
qt6-qtremoteobjects
qt6-qtscxml
qt6-qtsensors
qt6-qtserialbus
qt6-qtserialport
qt6-qtshadertools
qt6-qtspeech
qt6-qtsvg
qt6-qttools
qt6-qttranslations
qt6-qtvirtualkeyboard
qt6-qtwayland
qt-creator
How to mitigate CVE-2025-10729
dtk6log - update to 0.0.2-13.fc42
zeal - update to 0.7.2-14.fc42
nheko - update to 0.12.1-10.fc42
kddockwidgets - update to 1.7.0-27.fc42
LabPlot - update to 2.12.1-11.fc42
gammaray - update to 3.1.0-15.fc42
fcitx5-qt - update to 5.1.10-10.fc42
qt5-qtsvg-debugsource - addressed in versions 5.15.2-2, 5.15.10-2
qt5-qtsvg-devel - addressed in versions 5.15.2-2, 5.15.10-2
qt5-qtsvg-debuginfo - addressed in versions 5.15.2-2, 5.15.10-2
qt5-qtsvg - addressed in versions 5.15.2-2, 5.15.10-2
qt5-qtsvg-examples - update to 5.15.10-2
qt5-qtsvg - addressed in versions 5.15.17-2.el10_2, 5.15.17-2.fc41, 5.15.17-2.fc42, 5.15.17-3.fc43
mingw-qt5-qtsvg - addressed in versions 5.15.17-3.fc41, 5.15.17-3.fc42, 5.15.17-3.fc43
dtk6widget - update to 6.0.27-10.fc42
dtk6core - update to 6.0.27-11.fc42
dtk6gui - update to 6.0.27-12.fc42
qt6-qtsvg (Red Hat package) - addressed in versions 6.8.1-1.el10_0.1, 6.9.1-2.el10_1.1
mingw-qt6-qtsvg - addressed in versions 6.8.3-2.fc41, 6.9.2-2.fc42, 6.9.2-2.fc43, 6.9.3-1.fc42
python-pyqt6 - update to 6.9.0-5.fc42
dev-qt/qtsvg - update to 6.9.3
mingw-qt6-qtscxml - update to 6.9.3-1.fc42
mingw-qt6-qtmultimedia - update to 6.9.3-1.fc42
mingw-qt6-qtsensors - update to 6.9.3-1.fc42
mingw-qt6-qtserialport - update to 6.9.3-1.fc42
mingw-qt6-qtshadertools - update to 6.9.3-1.fc42
mingw-qt6-qttools - update to 6.9.3-1.fc42
mingw-qt6-qttranslations - update to 6.9.3-1.fc42
qt6-qtbase - update to 6.9.3-1.fc42
mingw-qt6-qtwebchannel - update to 6.9.3-1.fc42
qt6-qtwebview - update to 6.9.3-1.fc42
qt6-qtwebsockets - update to 6.9.3-1.fc42
qt6-qtcharts - update to 6.9.3-1.fc42
mingw-qt6-qtpositioning - update to 6.9.3-1.fc42
qt6-qtwebengine - update to 6.9.3-1.fc42
mingw-qt6-qtlocation - update to 6.9.3-1.fc42
mingw-qt6-qtimageformats - update to 6.9.3-1.fc42
mingw-qt6-qtdeclarative - update to 6.9.3-1.fc42
mingw-qt6-qtcharts - update to 6.9.3-1.fc42
mingw-qt6-qtbase - update to 6.9.3-1.fc42
mingw-qt6-qtactiveqt - update to 6.9.3-1.fc42
mingw-qt6-qt5compat - update to 6.9.3-1.fc42
mingw-qt6-qt3d - update to 6.9.3-1.fc42
qt6-qt5compat - update to 6.9.3-1.fc42
qt6-qt3d - update to 6.9.3-1.fc42
qt6 - update to 6.9.3-1.fc42
mingw-qt6-qtwebsockets - update to 6.9.3-1.fc42
qt6-qtquick3d - update to 6.9.3-1.fc42
qt6-qtcoap - update to 6.9.3-1.fc42
qt6-qtconnectivity - update to 6.9.3-1.fc42
qt6-qtdatavis3d - update to 6.9.3-1.fc42
qt6-qtdeclarative - update to 6.9.3-1.fc42
qt6-qthttpserver - update to 6.9.3-1.fc42
qt6-qtimageformats - update to 6.9.3-1.fc42
qt6-qtlanguageserver - update to 6.9.3-1.fc42
qt6-qtlocation - update to 6.9.3-1.fc42
qt6-qtlottie - update to 6.9.3-1.fc42
qt6-qtmqtt - update to 6.9.3-1.fc42
qt6-qtmultimedia - update to 6.9.3-1.fc42
qt6-qtnetworkauth - update to 6.9.3-1.fc42
qt6-qtopcua - update to 6.9.3-1.fc42
qt6-qtpositioning - update to 6.9.3-1.fc42
qt6-qtwebchannel - update to 6.9.3-1.fc42
qt6-qtquick3dphysics - update to 6.9.3-1.fc42
qt6-qtquicktimeline - update to 6.9.3-1.fc42
qt6-qtremoteobjects - update to 6.9.3-1.fc42
qt6-qtscxml - update to 6.9.3-1.fc42
qt6-qtsensors - update to 6.9.3-1.fc42
qt6-qtserialbus - update to 6.9.3-1.fc42
qt6-qtserialport - update to 6.9.3-1.fc42
qt6-qtshadertools - update to 6.9.3-1.fc42
qt6-qtspeech - update to 6.9.3-1.fc42
qt6-qtsvg - update to 6.9.3-1.fc42
qt6-qttools - update to 6.9.3-1.fc42
qt6-qttranslations - update to 6.9.3-1.fc42
qt6-qtvirtualkeyboard - update to 6.9.3-1.fc42
qt6-qtwayland - update to 6.9.3-1.fc42
qt-creator - update to 16.0.2-3.fc42
External References
Related Security Bulletins
- Multiple vulnerabilities in Qt
- Fedora 42 update for qt5-qtsvg
- Fedora 43 update for qt5-qtsvg
- Fedora EPEL 10.2 update for qt5-qtsvg
- Fedora 41 update for qt5-qtsvg
- Fedora 43 update for mingw-qt5-qtsvg, mingw-qt6-qtsvg
- Fedora 41 update for mingw-qt5-qtsvg, mingw-qt6-qtsvg
- Fedora 42 update for mingw-qt5-qtsvg, mingw-qt6-qtsvg
- Fedora 42 update for LabPlot, dtk6core, dtk6gui, dtk6log, dtk6widget, fcitx5-qt, gammaray, kddockwidgets, mingw-qt6-qt3d, mingw-qt6-qt5compat, mingw-qt6-qtactiveqt, mingw-qt6-qtbase, mingw-qt6-qtcharts, mingw-qt6-qtdeclarative, mingw-qt6-qtimageformats, m
- Red Hat Enterprise Linux 10 update for qt6-qtsvg
- Red Hat Enterprise Linux 10 update for qt6-qtsvg
- Gentoo update for qtsvg
- openEuler 22.03 LTS SP4 update for qt5-qtsvg
- openEuler 24.03 LTS SP3 update for qt5-qtsvg
- openEuler 24.03 LTS SP2 update for qt5-qtsvg
- openEuler 24.03 LTS SP1 update for qt5-qtsvg
- openEuler 24.03 LTS update for qt5-qtsvg