CVE-2025-6338

EUVD-2025-34743
There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.

This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
TQtCCNA
9.2 CRITICAL
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 32.64%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
qtqt
5.15.0 ≤
𝑥
≤ 6.8.3
CNA
qtqt
6.9.0 ≤
𝑥
< 6.9.2
CNA
Debian logo
Debian Releases
Debian Product
Codename
qt6-base
bookworm
6.4.2+dfsg-10
fixed
forky
6.10.2+dfsg-16
fixed
sid
6.10.2+dfsg-16
fixed
trixie
6.8.2+dfsg-9+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qt6-base
jammy
not-affected
noble
not-affected
plucky
not-affected
questing
not-affected