CVE-2025-3512
Buffer overflow in QTextMarkdownImporter
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.0 are known to be unaffected, and the fix is in 6.8.4 and later.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Clear
Affected products
The Qt Company · QtWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://codereview.qt-project.org/c/qt/qtbase/+/635546http://www.openwall.com/lists/oss-security/2025/04/24/4http://www.openwall.com/lists/oss-security/2025/04/24/5http://www.openwall.com/lists/oss-security/2025/04/24/6http://www.openwall.com/lists/oss-security/2025/04/25/1http://www.openwall.com/lists/oss-security/2025/04/25/2