CVE-2024-39936

HIGH

Qt < 5.15.18 - Time-of-check Time-of-use Race Condition in HTTP2 Connection Handling

Title source: llm
STIX 2.1

Description

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

Scores

CVSS v3 8.6
EPSS 0.0049
EPSS Percentile 38.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (1)
qt/qt < 5.15.18
Published Jul 04, 2024
Tracked Since Feb 18, 2026