Passing values outside of expected range to QColorTransferGenericFunction can cause a denial of service
Published Jul 11, 2025
2.3
LOWCVSS 4.0
EPSS 0.29%
Description
When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to QColorSpace::fromICCProfile.
This issue affects Qt from 6.6.0 through 6.8.3, from 6.9.0 through 6.9.1. This is fixed in 6.8.4 and 6.9.2.
Affected products
-
- Version 6.6.0StatusaffectedConstraints<=6.8.3
- Version 6.9.0StatusaffectedConstraints<=6.9.1
- Version 6.0.0StatusunaffectedConstraints<6.6.0
- Version 6.8.4StatusunaffectedConstraints<=6.8.3
- Version 6.9.2StatusunaffectedConstraints<=6.9.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
qt6
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | qt6 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jul 11, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.29% (0.00293) | 19.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.28% (0.00278) | 19.29th | v5 (v2026.06.15) |
| Jul 11, 2025 | 0.06% (0.00063) | 20.14th | v4 (v2025.03.14) |
References (5)
- https://access.redhat.com/security/cve/CVE-2025-5992 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2379493 Issue Tracking
- https://codereview.qt-project.org/c/qt/qtbase/+/647919
- https://nvd.nist.gov/vuln/detail/CVE-2025-5992
- https://www.cve.org/CVERecord?id=CVE-2025-5992
Change history (0)
No recorded changes yet.