Home

Description

There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.

PUBLISHED Reserved 2025-06-19 | Published 2025-10-16 | Updated 2025-10-16 | Assigner TQtC




CRITICAL: 9.2CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

Problem types

CWE-459 Incomplete Cleanup

Product status

Default status
unaffected

Any version before 5.15.0
unaffected

5.15.0
affected

6.8.4 before 6.9.0
unaffected

6.9.0 before 6.9.2
affected

References

codereview.qt-project.org/c/qt/qtbase/+/651495

cve.org (CVE-2025-6338)

nvd.nist.gov (CVE-2025-6338)

Download JSON