Skip to main content

Security advisory: A Heap-buffer-overflow issue in QTextMarkdownImporter impacts Qt

Comments

A Heap-buffer-overflow issue in QTextMarkdownImporter has been discovered and has been assigned the CVE id CVE-2025-3512.

Affected versions: From 6.8.0 up to 6.8.3. Versions before 6.6.0 are known to be unaffected.

Impact: Passing an incorrectly formatted markdown file to QTextMarkdownImporter can trigger a heap-buffer-overflow.

Solution: Apply the following patch or update to Qt 6.9.0 or 6.8.4

Patches:

Qt 6.8: https://codereview.qt-project.org/c/qt/qtbase/+/635699 or https://download.qt.io/official_releases/qt/6.8/CVE-2025-3512-qtbase-6.8.diff

Comments

Subscribe to our blog

Try Qt 6.10 Now!

Download the latest release here: www.qt.io/download

Qt 6.10 is now available, with new features and improvements for application developers and device creators.

We're Hiring

Check out all our open positions here and follow us on Instagram to see what it's like to be #QtPeople.