CVE-2023-37369: Debian Linux

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Qt Qt: before 5.15.15 (fixed in 5.15.15); from 6.0.0, before 6.2.9 (fixed in 6.2.9); from 6.3.0, before 6.5.2 (fixed in 6.5.2)

Published 2023-08-20. Last modified 2026-06-17.