PT-2024-26861 · Qt Company+3 · Qt+3

CVE-2024-36048

·

Published

2024-05-18

·

Updated

2025-10-10

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qt versions prior to 5.15.17 Qt versions 6.x prior to 6.2.13 Qt versions 6.3.x through 6.5.x prior to 6.5.6 Qt versions 6.6.x through 6.7.x prior to 6.7.1
Description The issue concerns QAbstractOAuth in Qt Network Authorization, where it uses only the time to seed the PRNG, which may result in guessable values.
Recommendations For Qt versions prior to 5.15.17, update to version 5.15.17 or later. For Qt versions 6.x prior to 6.2.13, update to version 6.2.13 or later. For Qt versions 6.3.x through 6.5.x prior to 6.5.6, update to version 6.5.6 or later. For Qt versions 6.6.x through 6.7.x prior to 6.7.1, update to version 6.7.1 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12243
ALT-PU-2025-12245
ALT-PU-2025-12246
ALT-PU-2025-12247
ALT-PU-2025-12248
ALT-PU-2025-12249
ALT-PU-2025-12250
ALT-PU-2025-12251
ALT-PU-2025-12252
ALT-PU-2025-12253
ALT-PU-2025-12254
ALT-PU-2025-12255
ALT-PU-2025-12256
ALT-PU-2025-12257
ALT-PU-2025-12258
ALT-PU-2025-12259
ALT-PU-2025-12260
ALT-PU-2025-12261
ALT-PU-2025-12262
ALT-PU-2025-12263
ALT-PU-2025-12264
ALT-PU-2025-12265
ALT-PU-2025-12266
ALT-PU-2025-12267
ALT-PU-2025-12268
ALT-PU-2025-12269
ALT-PU-2025-12270
ALT-PU-2025-12271
ALT-PU-2025-12272
ALT-PU-2025-12274
ALT-PU-2025-12275
ALT-PU-2025-12276
ALT-PU-2025-12277
ALT-PU-2025-12278
BDU:2025-08575
CVE-2024-36048
MGASA-2024-0197
OESA-2025-1140
OESA-2025-1141
OESA-2025-1142
OESA-2025-1143
OPENSUSE-SU-2024:0138-1
OPENSUSE-SU-2024:0143-1
OPENSUSE-SU-2024:14003-1
OPENSUSE-SU-2024:14006-1
ROSA-SA-2025-2600

Affected Products

Alt Linux
Debian
Qt
Red Os