CVE-2024-36048: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.

Affected products

  • Fedoraproject Fedora: version 39 only; version 40 only
  • Qt Qt: before 5.15.17 (fixed in 5.15.17); from 6.0.0, before 6.2.13 (fixed in 6.2.13); from 6.3.0, before 6.5.6 (fixed in 6.5.6); from 6.6.0, before 6.7.1 (fixed in 6.7.1)

Published 2024-05-18. Last modified 2026-06-17.