CVE-2025-12385

NameCVE-2025-12385
DescriptionAllocation of Resources Without Limits or Throttling, Improper Validat ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1122054, 1122055, 1122056

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qt6-declarative (PTS)bookworm6.4.2+dfsg-1vulnerable
trixie6.8.2+dfsg-7vulnerable
forky, sid6.10.2+dfsg-4vulnerable
qtdeclarative-opensource-src (PTS)bullseye5.15.2+dfsg-6vulnerable
bookworm5.15.8+dfsg-3vulnerable
trixie5.15.15+dfsg-3vulnerable
forky, sid5.15.17+dfsg-4fixed
qtdeclarative-opensource-src-gles (PTS)bullseye5.15.2+dfsg-2vulnerable
bookworm5.15.8+dfsg-1vulnerable
trixie5.15.15+dfsg-2vulnerable
forky, sid5.15.17+dfsg-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qt6-declarativesource(unstable)(unfixed)1122054
qtdeclarative-opensource-srcsource(unstable)5.15.17+dfsg-41122055
qtdeclarative-opensource-src-glessourceexperimental5.15.18+dfsg-1
qtdeclarative-opensource-src-glessource(unstable)(unfixed)1122056

Notes

[trixie] - qt6-declarative <no-dsa> (Minor issue)
[bookworm] - qt6-declarative <no-dsa> (Minor issue)
[trixie] - qtdeclarative-opensource-src <no-dsa> (Minor issue)
[bookworm] - qtdeclarative-opensource-src <no-dsa> (Minor issue)
[bullseye] - qtdeclarative-opensource-src <postponed> (Minor issue)
[trixie] - qtdeclarative-opensource-src-gles <no-dsa> (Minor issue)
[bookworm] - qtdeclarative-opensource-src-gles <no-dsa> (Minor issue)
[bullseye] - qtdeclarative-opensource-src-gles <postponed> (Minor issue)
https://codereview.qt-project.org/c/qt/qtdeclarative/+/687239
https://codereview.qt-project.org/c/qt/qtdeclarative/+/687766

Search for package or bug name: Reporting problems