The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.
CVSS Details
- CVSS 4.0 Base Score: 9.4 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:X/R:X/V:X/RE:H/U:Red)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade qt5-qtsvg-examplesUpgrade qt5-qtsvgUpgrade qt5-qtsvg-debuginfoUpgrade qt5-qtsvg-devel | May 20, 2026 | May 20, 2026 |
| Gentoo Linux | — | Upgrade dev-qt/qtsvg. | Nov 25, 2025 | Nov 24, 2025 |
| Oracle_linux | — | Upgrade qt6-qtsvgUpgrade qt6-qtsvg-develUpgrade qt6-qtsvg-examples | Nov 7, 2025 | Oct 3, 2025 |
| Redhat_linux | — | Upgrade qt6-qtsvg-develUpgrade qt6-qtsvg-tests-debuginfoUpgrade qt6-qtsvg-debuginfoUpgrade qt6-qtsvg-debugsourceUpgrade qt6-qtsvg-examplesNo solution existsUpgrade qt6-qtsvg | Jan 27, 2026 | Oct 3, 2025 |
| Rocky_linux | — | Upgrade qt6-qtsvg-develUpgrade qt6-qtsvg-debuginfoUpgrade qt6-qtsvgUpgrade qt6-qtsvg-debugsourceUpgrade qt6-qtsvg-examples | Feb 5, 2026 | Nov 21, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub