Описание
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| qt6-connectivity | fixed | 6.7.2-8 | package | |
| qt6-connectivity | no-dsa | bookworm | package | |
| qtconnectivity-opensource-src | fixed | 5.15.15-3 | package | |
| qtconnectivity-opensource-src | no-dsa | bookworm | package | |
| qtconnectivity-opensource-src | postponed | bullseye | package |
Примечания
https://www.qt.io/blog/security-advisory-qlowenergycontroller-on-linux
https://github.com/qt/qtconnectivity/commit/aecbd657c841a2a8c74631ceac96b8ff1f03ab5c (dev)
https://download.qt.io/official_releases/qt/5.15/CVE-2025-23050-qtconnectivity-5.15.diff
EPSS
Связанные уязвимости
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
Уязвимость функций processUnsolicitedReply() и processReply() файла bluetooth/qlowenergycontroller_bluez.cpp кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю выполнить произвольный код
EPSS