Qt: Buffer Overflow A vulnerability has been discovered in Qt, where a buffer overflow can lead to denial of service. qtbase,qtcore 2025-01-23 2025-01-23 911790 local 6.5.2 6.5.2 5.15.10-r1 5.15.10-r1

Qt is a cross-platform application development framework.

When given specifically crafted data then QXmlStreamReader can end up causing a buffer overflow and subsequently a crash or freeze or get out of memory on recursive entity expansion, with DTD tokens in XML body.

Please review the referenced CVE identifiers for details.

There is no known workaround at this time.

All Qt users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-qt/qtcore-5.15.10-r1" # emerge --ask --oneshot --verbose ">=dev-qt/qtbase-6.5.2"
CVE-2023-37369 CVE-2023-38197 graaff graaff