CVE-2025-14575
EUVD-2025-20989119.05.2026, 14:16
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| qt | qt | 5.0.0 ≤ 𝑥 ≤ 5.15.19 | CNA |
| qt | qt | 6.0.0 ≤ 𝑥 ≤ 6.5.9 | CNA |
| qt | qt | 6.6.0 ≤ 𝑥 ≤ 6.8.3 | CNA |
| qt | qt | 6.9.0 ≤ 𝑥 ≤ 6.9.1 | CNA |
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qt6-base |
| ||||||||||||||
| qtbase-opensource-src |
| ||||||||||||||
| qtbase-opensource-src-gles |
|
openSUSE / SLES Releases
openSUSE Product | |||
|---|---|---|---|
| libqt4 |
| ||
| libqt4-32bit |
| ||
| libqt4-qt3support |
| ||
| libqt4-qt3support-32bit |
| ||
| libqt4-sql |
| ||
| libqt4-sql-32bit |
| ||
| libqt4-sql-mysql |
| ||
| libqt4-sql-sqlite |
| ||
| libqt4-x11 |
| ||
| libqt4-x11-32bit |
| ||
| qt4-x11-tools |
|
Common Weakness Enumeration