Executive brief
A flaw exists in the Qt SVG library, which is used by many applications to display scalable graphics. An attacker could potentially crash an application or cause unpredictable behavior by providing a specially crafted SVG file. This could lead to service interruptions for users of software built with this library.
Technical details
A use-after-free vulnerability exists in the Qt SVG module's handling of <pattern> nodes. The parser incorrectly processes a <pattern> node that is not a child of a structural node, leading to the node being deleted immediately after creation while remaining accessible for later operations. An attacker who can provide a malicious SVG file to an application using Qt SVG could trigger this memory corruption. This could result in a denial of service (crash) or potentially arbitrary code execution, though the latter is more complex to achieve. A patch has been proposed in the Qt project's Gerrit code review system.
Affected products
- Qt Group Qt SVG 6.x
Timeline
- 2025-10-03: disclosed: CVE published