Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22394 - Security Advisory
Issued:
2025-12-01
Updated:
2025-12-01

RHSA-2025:22394 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: qt6-qtsvg security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for qt6-qtsvg is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Scalable Vector Graphics (SVG) is an XML-based language for describing two-dimensional vector graphics. Qt provides classes for rendering and displaying SVG drawings in widgets and on other paint devices.

Security Fix(es):

  • qtsvg: Uncontrolled recursion in Qt SVG module (CVE-2025-10728)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 10 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 10 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x

Fixes

  • BZ - 2401244 - CVE-2025-10728 qtsvg: Uncontrolled recursion in Qt SVG module

CVEs

  • CVE-2025-10728

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
qt6-qtsvg-6.9.1-2.el10_1.2.src.rpm SHA-256: 609fca12d87fd09123de9a287589ff089f20b8219b1d43e707e34b5934147c6b
x86_64
qt6-qtsvg-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: e368a182af4bfea5b6487a9cc4b0d1e94700f7b817955d00d8dd3f1c80ffdcd1
qt6-qtsvg-debuginfo-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: 000445e58fa3254352edab8a8ca09fa507a790d9dddf34b7573512fdd263ea06
qt6-qtsvg-debugsource-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: b1a3fd1397b337a519a3b36a55ac2493c516c1efc4f73ed65c5150928590029d
qt6-qtsvg-devel-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: ca132931ce957e77ea69556f3bf33419318bab1a099e322578c02725b70123e0
qt6-qtsvg-tests-debuginfo-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: adcbcc5b02c62461eaf98813c774df86dd0ae799810fb05ef71f58f7fa3fd5e5

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
qt6-qtsvg-6.9.1-2.el10_1.2.src.rpm SHA-256: 609fca12d87fd09123de9a287589ff089f20b8219b1d43e707e34b5934147c6b
s390x
qt6-qtsvg-6.9.1-2.el10_1.2.s390x.rpm SHA-256: f01f13d7f73f806e2a6f173dff1e98a072557f19b11611e2aff9960e8033951a
qt6-qtsvg-debuginfo-6.9.1-2.el10_1.2.s390x.rpm SHA-256: 1e713600da4b6a29f018747f56ee839c3775d45a4399aafb1dad91a555185d76
qt6-qtsvg-debugsource-6.9.1-2.el10_1.2.s390x.rpm SHA-256: a6db4c0f09f4f8331a96b8a23b896c451041fa7ba723505fb852ce546cf53e88
qt6-qtsvg-devel-6.9.1-2.el10_1.2.s390x.rpm SHA-256: eb4ca713efec0dfc0e5f1573a8680bfe3f8345ba7c00f643318ae364f4392d44
qt6-qtsvg-tests-debuginfo-6.9.1-2.el10_1.2.s390x.rpm SHA-256: c8944963324503a8fa74002cf4756db811e66d89e3b204d242ec70b29ec37174

Red Hat Enterprise Linux for Power, little endian 10

SRPM
qt6-qtsvg-6.9.1-2.el10_1.2.src.rpm SHA-256: 609fca12d87fd09123de9a287589ff089f20b8219b1d43e707e34b5934147c6b
ppc64le
qt6-qtsvg-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: cb23dac248dec5570519e42d1697b6e413b7a35b2e88e8dcbee7f7dbd7e81140
qt6-qtsvg-debuginfo-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: c4896ed3f16fc8b6158d13948c0304e8e65c31fc8e26782d928145c0fbeda196
qt6-qtsvg-debugsource-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: 7781e05047d8688d16d6da001266b6c5e41fb76d579d71426f5822e246fe0a7e
qt6-qtsvg-devel-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: b4ddd3783afecf3e8ffe4a8cda0eafeef71456ea20000656852d32b5b87f61b6
qt6-qtsvg-tests-debuginfo-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: 086b8e6e903f8c05fd5d7e5028050acd2b1dde07d442895e1e2433935f5d739c

Red Hat Enterprise Linux for ARM 64 10

SRPM
qt6-qtsvg-6.9.1-2.el10_1.2.src.rpm SHA-256: 609fca12d87fd09123de9a287589ff089f20b8219b1d43e707e34b5934147c6b
aarch64
qt6-qtsvg-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: e88d19f8a5e9dcc0d3a3782cf09b97d57f806bda067fe60f270e4db2b50ac102
qt6-qtsvg-debuginfo-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: ecf14d55856f1005b8532abb7edd8ce5ac2ba1d5be26e680f35f5fbc9fc28e65
qt6-qtsvg-debugsource-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: b5dce472932a97817a8b451bc1afcebb81c226ca92d7da127e3d9afc7ba3645f
qt6-qtsvg-devel-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: 91a7cf86652ba141b8106b3e6017cf1b88f7d40ee28d97a362dc919057886340
qt6-qtsvg-tests-debuginfo-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: 678f6b584bd94409322b387f81a72e112cb34196b8833c17b1b06f8131edc796

Red Hat CodeReady Linux Builder for x86_64 10

SRPM
x86_64
qt6-qtsvg-debuginfo-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: 000445e58fa3254352edab8a8ca09fa507a790d9dddf34b7573512fdd263ea06
qt6-qtsvg-debugsource-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: b1a3fd1397b337a519a3b36a55ac2493c516c1efc4f73ed65c5150928590029d
qt6-qtsvg-examples-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: 7a43261a77288de6cf14fee7569587e5fe1b37381c3143dbd072662df12b729a
qt6-qtsvg-tests-debuginfo-6.9.1-2.el10_1.2.x86_64.rpm SHA-256: adcbcc5b02c62461eaf98813c774df86dd0ae799810fb05ef71f58f7fa3fd5e5

Red Hat CodeReady Linux Builder for Power, little endian 10

SRPM
ppc64le
qt6-qtsvg-debuginfo-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: c4896ed3f16fc8b6158d13948c0304e8e65c31fc8e26782d928145c0fbeda196
qt6-qtsvg-debugsource-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: 7781e05047d8688d16d6da001266b6c5e41fb76d579d71426f5822e246fe0a7e
qt6-qtsvg-examples-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: be7a4b9c5a2bdbb59770b569b31080eb4c29c9bd29da49ff249956795cdbffe3
qt6-qtsvg-tests-debuginfo-6.9.1-2.el10_1.2.ppc64le.rpm SHA-256: 086b8e6e903f8c05fd5d7e5028050acd2b1dde07d442895e1e2433935f5d739c

Red Hat CodeReady Linux Builder for ARM 64 10

SRPM
aarch64
qt6-qtsvg-debuginfo-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: ecf14d55856f1005b8532abb7edd8ce5ac2ba1d5be26e680f35f5fbc9fc28e65
qt6-qtsvg-debugsource-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: b5dce472932a97817a8b451bc1afcebb81c226ca92d7da127e3d9afc7ba3645f
qt6-qtsvg-examples-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: 36cd12335c9cd058a47af328cedd6ae0b677fb7fe01fa2bcc950e187bb492f3c
qt6-qtsvg-tests-debuginfo-6.9.1-2.el10_1.2.aarch64.rpm SHA-256: 678f6b584bd94409322b387f81a72e112cb34196b8833c17b1b06f8131edc796

Red Hat CodeReady Linux Builder for IBM z Systems 10

SRPM
s390x
qt6-qtsvg-debuginfo-6.9.1-2.el10_1.2.s390x.rpm SHA-256: 1e713600da4b6a29f018747f56ee839c3775d45a4399aafb1dad91a555185d76
qt6-qtsvg-debugsource-6.9.1-2.el10_1.2.s390x.rpm SHA-256: a6db4c0f09f4f8331a96b8a23b896c451041fa7ba723505fb852ce546cf53e88
qt6-qtsvg-examples-6.9.1-2.el10_1.2.s390x.rpm SHA-256: bdf378c1ad5c1931313820006d24d780c9c81e5e360828f1a27dd2d345605bb5
qt6-qtsvg-tests-debuginfo-6.9.1-2.el10_1.2.s390x.rpm SHA-256: c8944963324503a8fa74002cf4756db811e66d89e3b204d242ec70b29ec37174

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility