{"id":"MGASA-2025-0212","summary":"Updated qtbase6 & qtbase5 packages fix security vulnerability","details":"An issue was found in the private API function qDecodeDataUrl() in\nQtCore, which is used in QTextDocument and QNetworkReply, and,\npotentially, in user code. If the function was called with malformed\ndata, for example, an URL that contained a \"charset\" parameter that\nlacked a value (such as \"data:charset,\"), and Qt was built with\nassertions enabled, then it would hit an assertion, resulting in a\ndenial of service (abort). This impacts Qt up to 5.15.18, 6.0.0-\u003e6.5.8,\n6.6.0-\u003e6.8.3 and 6.9.0.\n","modified":"2026-04-16T00:11:10.496277666Z","published":"2025-07-22T16:34:04Z","upstream":["CVE-2025-5455"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0212.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=34444"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/KQMS4MZAS4ACVLXLPAIC3JKRWOKIVJS7/"}],"affected":[{"package":{"name":"qtbase6","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/qtbase6?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.1-5.2.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0212.json"}},{"package":{"name":"qtbase5","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/qtbase5?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.7-6.2.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0212.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}