CVE-2023-45935

Publication date 27 March 2024

Last updated 4 August 2025


Ubuntu priority

Cvss 3 Severity Score

4.2 · Medium

Score breakdown

Description

Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server.

Status

Package Ubuntu Release Status
qt6-base 24.04 LTS noble
Not affected
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
Not affected
20.04 LTS focal Not in release

Severity score breakdown

Parameter Value
Base score 4.2 · Medium
Attack vector Local
Attack complexity Low
Privileges required High
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H