{"id":"CVE-2023-38197","details":"An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.","modified":"2026-04-10T04:58:59.179989Z","published":"2023-07-13T02:15:09.677Z","related":["ALSA-2023:6369","ALSA-2023:6967","SUSE-SU-2023:2971-1","SUSE-SU-2023:2982-1","SUSE-SU-2023:3018-1","SUSE-SU-2023:3207-1","SUSE-SU-2023:3225-1","SUSE-SU-2023:3380-1","SUSE-SU-2023:4622-1","SUSE-SU-2025:02968-1","openSUSE-SU-2024:13079-1","openSUSE-SU-2024:13377-1"],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/04/msg00027.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F5C3NYVJ73ITE6HUOVVHBUAGORVEJRHO/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XEGQ6DFTL2BEJMHCD5FJGI6XLWQI7UEA/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFZORZYCMUZZFIOEZICJ7VH2BZIGY3HV/"},{"type":"FIX","url":"https://codereview.qt-project.org/c/qt/qtbase/+/488960"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qt/qtbase","events":[{"introduced":"0"},{"fixed":"ca725ad9c5331a657c328bf624f2b0b713623276"},{"introduced":"fc9cda5f08ac848e88f63dd4a07c08b2fbc6bf17"},{"fixed":"017d80e12fa50c50fa6751a039d3a7c9e799f34c"},{"introduced":"9554d315aa74eaba1726405ee09117e2ebc6111f"},{"fixed":"372eaedc5b8c771c46acc4c96e91bbade4ca3624"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"5.15.15"},{"introduced":"6.0.0"},{"fixed":"6.2.10"},{"introduced":"6.3.0"},{"fixed":"6.5.3"}]}}],"versions":["v5.0.0-beta1","v5.0.0-beta2","v5.15.0-alpha1","v5.15.0-beta1","v5.15.0-beta2","v5.15.0-beta3","v5.15.0-beta4","v5.15.10-lts-lgpl","v5.15.11-lts-lgpl","v5.15.12-lts-lgpl","v5.15.13-lts-lgpl","v5.15.14-lts-lgpl","v5.15.3-lts-lgpl","v5.15.4-lts-lgpl","v5.15.5-lts-lgpl","v5.15.6-lts-lgpl","v5.15.7-lts-lgpl","v5.15.8-lts-lgpl","v5.15.9-lts-lgpl","v6.0.0-alpha1","v6.0.0-beta1","v6.0.0-beta2","v6.0.0-beta3","v6.0.0-beta4","v6.0.0-beta5","v6.2.0-alpha1","v6.2.0-beta1","v6.2.0-beta2","v6.2.0-beta3","v6.2.0-beta4","v6.2.5-lts-lgpl","v6.2.6-lts-lgpl","v6.2.7-lts-lgpl","v6.2.8-lts-lgpl","v6.2.9-lts-lgpl","v6.5.0-beta1","v6.5.0-beta2","v6.5.0-beta3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38197.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}