Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-36915.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-36915
Upstream
Published
2024-03-27T03:15:12Z
Modified
2026-04-01T05:12:17.037384Z
Summary
CVE-2024-25580 affecting package qt5-qtbase for versions less than 5.12.11-15
Details

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.

References

Affected packages

Azure Linux:2 / qt5-qtbase

Package

Name
qt5-qtbase
Purl
pkg:rpm/azure-linux/qt5-qtbase

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.12.11-15

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-36915.json"