Status: UPDATED
| Advisory ID: CVE-2025-14576
Key Details
| CVE | CVE-2025-14576 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-10-07 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Hardened Images, qt qtdeclarative, and qt Qt |
| Classified as | CWE-20 (Improper Input Validation) |
Affected Products, Subsystems & Sectors
| Subsystems | OT Supporting Infrastructure |
| Sectors | Multiple |
What to Know
Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access. (NVD)
What to Do
Monitor Red Hat's and qt's web pages for any future patch releases.
References