Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.
Conclusion & alert: CVE-2023-24607 is rated Moderate Risk (54.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.32%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.35% | 1.32% | +0.97% |
| 2 | 2026-05-03 | 0.32% | 0.35% | +0.03% |
| 3 | 2025-11-29 | — | 0.32% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2023-24607 unimportant priority: Debian including 3 source packages (qt6-base, qtbase-opensource-src, qtbase-opensource-src-gles), 14 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 14. | https://security-tracker.debian.org/tracker/CVE-2023-24607 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-24607 |
suse
|
high | CVE-2023-24607 severity important: SUSE including 1019 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 2272 product×package rows across 87 product lines (Container suse/sl-micro/6.0/toolbox, Image SLE-Micro, … (87 product lines)): Fixed 1593, Known Not Affected 448, Known Affected 231. | https://www.suse.com/security/cve/CVE-2023-24607/ |
ubuntu
|
low | CVE-2023-24607 low priority: Ubuntu including 3 source packages (qt6-base, qtbase-opensource-src, qtbase-opensource-src-gles), 39 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 18, needs-triage 10, released 5, DNE 3, not-affected 3. | https://ubuntu.com/security/CVE-2023-24607 |
| URL | Tags |
|---|---|
| https://codereview.qt-project.org/c/qt/qtbase/+/456216 | Issue Tracking |
| https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/456217 | Permissions Required |
| https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/456238 | Permissions Required |
| https://download.qt.io/official_releases/qt/5.15/CVE-2023-24607-qtbase-5.15.diff | Vendor Advisory |
| https://github.com/qt/qtbase/commit/aaf1381eab6292aa0444a5eadcc24165b6e1c02d | Patch Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2024/04/msg00027.html | |
| https://www.qt.io/blog/security-advisory-qt-sql-odbc-driver-plugin | Product |
| https://www.qt.io/blog/tag/security | Release Notes |