The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://codereview.qt-project.org/c/qt/qtsvg/+/676473 |
![]() ![]() |
History
Fri, 03 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 03 Oct 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free. | |
Title | Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG | |
Weaknesses | CWE-416 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: TQtC
Published:
Updated: 2025-10-03T14:54:57.318Z
Reserved: 2025-09-19T14:01:08.672Z
Link: CVE-2025-10729

Updated: 2025-10-03T14:54:49.345Z

Status : Received
Published: 2025-10-03T16:16:16.777
Modified: 2025-10-03T16:16:16.777
Link: CVE-2025-10729

No data.

No data.