CVE-2025-12385

EUVD-2025-201103
Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation.


This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive.



This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
TQtCCNA
8.7 HIGH
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 23.89%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
qtqt
5.0.0 ≤
𝑥
≤ 6.5.10
CNA
qtqt
6.6.0 ≤
𝑥
≤ 6.8.5
CNA
qtqt
6.9.0 ≤
𝑥
≤ 6.10.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
qt6-declarative
bookworm
no-dsa
forky
vulnerable
sid
vulnerable
trixie
no-dsa
qtdeclarative-opensource-src
bookworm
no-dsa
bullseye
postponed
forky
5.15.19+dfsg-2
fixed
sid
5.15.19+dfsg-2
fixed
trixie
no-dsa
qtdeclarative-opensource-src-gles
bookworm
no-dsa
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qt6-declarative
jammy
needed
noble
needed
plucky
ignored
questing
ignored
resolute
needed
qtdeclarative-opensource-src
bionic
ignored
focal
Fixed 5.12.8-0ubuntu1+esm1
released
jammy
Fixed 5.15.3+dfsg-1ubuntu0.1~esm1
released
noble
Fixed 5.15.13+dfsg-1ubuntu0.1+esm1
released
plucky
ignored
questing
ignored
resolute
not-affected
xenial
ignored
qtdeclarative-opensource-src-gles
focal
needed
jammy
needed
noble
needed
plucky
ignored
questing
ignored
resolute
needed
xenial
needed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
qt5-qtbase
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-common
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-debuginfo
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-devel
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-examples
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-gui
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-mysql
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-odbc
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-postgresql
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-private-devel
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtbase-static
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtdeclarative
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtdeclarative-debuginfo
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtdeclarative-devel
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtdeclarative-examples
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
qt5-qtdeclarative-static
Amazon Linux 2
0:5.15.3-1.amzn2.0.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
qt5-qtdeclarative
CBL-Mariner 2.0
0:5.12.5-6.cm2
fixed
qtdeclarative
Azure Linux 3.0
0:6.6.1-2.azl3
fixed