vulnerability

Oracle Linux: CVE-2022-25255: ELSA-2022-7482: qt5 security, bug fix, and enhancement update (MODERATE) (Multiple Advisories)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Feb 16, 2022
Added
Nov 16, 2022
Modified
Dec 3, 2025

Description

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
A flaw was found in qt. The vulnerability occurs due to executing binaries from the current directory when the loading path failed, leading to an uncontrolled path element vulnerability. This flaw allows an attacker to execute malicious executables.

Solutions

oracle-linux-upgrade-qt5oracle-linux-upgrade-qt5-develoracle-linux-upgrade-qt5-rpm-macrosoracle-linux-upgrade-qt5-srpm-macros
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.