Allocation of Resources Without Limits or Throttling in Qt - CVE-2025-12385

 

Allocation of Resources Without Limits or Throttling in Qt - CVE-2025-12385

Published: December 3, 2025


Vulnerability identifier: #VU119114
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12385
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper allocation of resources in Text component parser of the Qt declarative module. A remote attacker can pass overly large values for the width and height in the <img> tag and cause an application to become unresponsive.


Affected software

Qt
Ubuntu
openEuler
qtdeclarative-opensource-src (Ubuntu package)
qt5-qtdeclarative-devel
qt5-qtdeclarative-debugsource
qt5-qtdeclarative-debuginfo
qt5-qtdeclarative
qt5-qtdeclarative-examples
qt5-qtdeclarative-static
qt6-qtdeclarative-debuginfo
qt6-qtdeclarative-debugsource
qt6-qtdeclarative-devel
qt6-qtdeclarative-examples
qt6-qtdeclarative-static
qt6-qtdeclarative

How to mitigate CVE-2025-12385

Install updates from vendor's website.

Qt - addressed in versions 6.5.11, 6.8.6, 6.10.1
qtdeclarative-opensource-src (Ubuntu package) - addressed in versions 5.12.8-0ubuntu1+esm1, 5.15.3+dfsg-1ubuntu0.1~esm1, 5.15.13+dfsg-1ubuntu0.1+esm1
qt5-qtdeclarative-devel - addressed in versions 5.15.2-2, 5.15.10-2
qt5-qtdeclarative-debugsource - addressed in versions 5.15.2-2, 5.15.10-2
qt5-qtdeclarative-debuginfo - addressed in versions 5.15.2-2, 5.15.10-2
qt5-qtdeclarative - addressed in versions 5.15.2-2, 5.15.10-2
qt5-qtdeclarative-examples - update to 5.15.10-2
qt5-qtdeclarative-static - update to 5.15.10-2
qt6-qtdeclarative-debuginfo - update to 6.5.2-2
qt6-qtdeclarative-debugsource - update to 6.5.2-2
qt6-qtdeclarative-devel - update to 6.5.2-2
qt6-qtdeclarative-examples - update to 6.5.2-2
qt6-qtdeclarative-static - update to 6.5.2-2
qt6-qtdeclarative - update to 6.5.2-2

External References

Related Security Bulletins