Security advisory: A Heap-buffer-overflow issue in QTextMarkdownImporter impacts Qt

A Heap-buffer-overflow issue in QTextMarkdownImporter has been discovered and has been assigned the CVE id CVE-2025-3512.

Affected versions: From 6.8.0 up to 6.8.3. Versions before 6.6.0 are known to be unaffected.

Impact: Passing an incorrectly formatted markdown file to QTextMarkdownImporter can trigger a heap-buffer-overflow.

Solution: Apply the following patch or update to Qt 6.9.0 or 6.8.4

Patches:

Qt 6.8: https://codereview.qt-project.org/c/qt/qtbase/+/635699 or https://download.qt.io/official_releases/qt/6.8/CVE-2025-3512-qtbase-6.8.diff


Blog Topics:

Comments