<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2026-0094</id>
    <title>An update for qt5-qtdeclarative is now available for HCE 2.0</title>
    <severity>Moderate</severity>
    <release>HCE 2.0</release>
    <issued date="2026-03-23 23:18:33"/>
    <updated date="2026-03-23 23:18:33"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-12385" id="CVE-2025-12385" title="CVE-2025-12385 Base Score: 5.0 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation.
This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the &lt;img&gt; tag could cause an application to become unresponsive.

This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0. (CVE-2025-12385)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="qt5-qtdeclarative">
        <name>HCE 2.0</name>
        <package arch="x86_64" name="qt5-qtdeclarative" version="5.15.2" release="1.r1.hce2">
          <filename>qt5-qtdeclarative-5.15.2-1.r1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="qt5-qtdeclarative-devel" version="5.15.2" release="1.r1.hce2">
          <filename>qt5-qtdeclarative-devel-5.15.2-1.r1.hce2.x86_64.rpm</filename>
        </package>
        <package arch="aarch64" name="qt5-qtdeclarative" version="5.15.2" release="1.r1.hce2">
          <filename>qt5-qtdeclarative-5.15.2-1.r1.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="qt5-qtdeclarative-devel" version="5.15.2" release="1.r1.hce2">
          <filename>qt5-qtdeclarative-devel-5.15.2-1.r1.hce2.aarch64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
