Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-38737.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-38737
Upstream
Published
2024-03-27T03:15:12Z
Modified
2026-04-01T05:13:21.200754Z
Summary
CVE-2024-25580 affecting package qtbase for versions less than 6.6.2-1
Details

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.

References

Affected packages

Azure Linux:3 / qtbase

Package

Name
qtbase
Purl
pkg:rpm/azure-linux/qtbase

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-38737.json"