There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period. This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.
The vulnerability results from improper release or cleanup of internal resources during network connection handling using the Schannel implementation in Qt Network on Windows. The accumulation of uncleaned resources over time causes gradual degradation of application performance, culminating in its unavailability or complete failure.
An attacker or prolonged usage may lead to denial of service — both in the context of the application itself (VC:N/VI:N/VA:H) and potentially the underlying system (SA:H). The impact affects service availability, not data confidentiality or integrity.
Qt should be updated to version 6.9.2 or later. For the 5.15.x and 6.8.x branches, patches available from the vendor should be applied according to references (codereview.qt-project.org/c/qt/qtbase/+/651495). As a temporary workaround, consider periodic restarts of services using Qt Network on Windows.
Qt in versions 5.15.0 to 6.8.3 (inclusive) and in version 6.9.0 to 6.9.1 (before 6.9.2). The vulnerability affects Windows only (Schannel support in Qt Network).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X