CVE-2025-5991 Affecting qtbase-opensource-src package, versions *


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.02% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1804-QTBASEOPENSOURCESRC-10597615
  • published25 Jul 2025
  • disclosed11 Jun 2025

Introduced: 11 Jun 2025

CVE-2025-5991  (opens in a new tab)

How to fix?

There is no fixed version for Ubuntu:18.04 qtbase-opensource-src.

NVD Description

Note: Versions mentioned in the description apply only to the upstream qtbase-opensource-src package and not the qtbase-opensource-src package as distributed by Ubuntu. See How to fix? for Ubuntu:18.04 relevant fixed versions and status.

There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how QHttp2Stream uploads the body of a POST request and the simultaneous handling of HTTP error responses.

This issue only affects Qt 6.9.0 and has been fixed for Qt 6.9.1.

CVSS Base Scores

version 3.1