Junglewise Threat Intelligence

CVE-2025-10729: Qt SVG use after free in pattern node parsing

CVE-2025-10729 · Severity: info · CVSS 0 · Published 2025-10-03

Vendors: Qt Group.

Executive brief

A flaw exists in the Qt SVG library, which is used by many applications to display scalable graphics. An attacker could potentially crash an application or cause unpredictable behavior by providing a specially crafted SVG file. This could lead to service interruptions for users of software built with this library.

Technical details

A use-after-free vulnerability exists in the Qt SVG module's handling of <pattern> nodes. The parser incorrectly processes a <pattern> node that is not a child of a structural node, leading to the node being deleted immediately after creation while remaining accessible for later operations. An attacker who can provide a malicious SVG file to an application using Qt SVG could trigger this memory corruption. This could result in a denial of service (crash) or potentially arbitrary code execution, though the latter is more complex to achieve. A patch has been proposed in the Qt project's Gerrit code review system.

Affected products

  • Qt Group Qt SVG 6.x

Timeline

  • 2025-10-03: disclosed: CVE published

References