Fedora Linux 9174 Published by

A security update for Fedora 42 has been released to address a use-after-free vulnerability in the qt5-qtsvg package, identified as CVE-2025-10729. The qt5-qtsvg package provides support for rendering and displaying Scalable Vector Graphics (SVG) on Fedora systems.

Fedora 42 Update: qt5-qtsvg-5.15.17-2.fc42




[SECURITY] Fedora 42 Update: qt5-qtsvg-5.15.17-2.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-151117f1f8
2025-10-14 01:41:31.058027+00:00
--------------------------------------------------------------------------------

Name : qt5-qtsvg
Product : Fedora 42
Version : 5.15.17
Release : 2.fc42
URL : http://www.qt.io
Summary : Qt5 - Support for rendering and displaying SVG
Description :
Scalable Vector Graphics (SVG) is an XML-based language for describing
two-dimensional vector graphics. Qt provides classes for rendering and
displaying SVG drawings in widgets and on other paint devices.

--------------------------------------------------------------------------------
Update Information:

Fix CVE-2025-10729
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Than Ngo [than@redhat.com] - 5.15.17-2
- Fix CVE-2025-10729
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402371 - CVE-2025-10729 qt5-qtsvg: Use-after-free vulnerability in Qt SVG [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2402371
[ 2 ] Bug #2402375 - CVE-2025-10729 qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402375
[ 3 ] Bug #2402379 - CVE-2025-10729 qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402379
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-151117f1f8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--