Opened 10 months ago

Closed 10 months ago

Last modified 9 months ago

#19970 closed enhancement (fixed)

qt6-6.7.2 qtwebengine-6.7.2

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: high Milestone: 12.2
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Bruce Dubbs, 10 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: newassigned

comment:2 by Bruce Dubbs, 10 months ago

Release note

Qt 6.7.2 release is a patch release made on the top of Qt 6.7.1. As a patch release, Qt 6.7.2 does not add any new functionality but provides bug fixes and other improvements and maintains both forward and backward compatibility (source and binary) with Qt 6.7.1.

comment:3 by Bruce Dubbs, 10 months ago

Resolution: fixed
Status: assignedclosed

Fixed at commit 7ef2fd3480.

comment:4 by Douglas R. Reno, 9 months ago

Priority: normalhigh

QtWebEngine 6.7.2 does include several security fixes for the bundled version of Chromium. The security fixes are as follows (and can be found at https://code.qt.io/cgit/qt/qtwebengine.git/commit/?h=6.7.2&id=8965919584f58a0ad9bb5b3c7f6b091fc47be34a):

  • CVE-2024-5493: Heap buffer overflow in WebRTC (High, rating issued by US CISA)
  • CVE-2024-5494: Use after free in Dawn (High, rating issued by US CISA)
  • CVE-2024-5495: Use after free in Dawn (High)
  • CVE-2024-5496: Use after free in Media Session (High, rating issued by US CISA)
  • CVE-2024-5499: Out of bounds write in Streams API (High, rating issued by US CISA)
  • CVE-2024-5274: Type Confusion in V8 (High, rating issued by US CISA)
  • CVE-2024-4948: Use after free in Dawn (High, rating issued by US CISA)

The ratings by US CISA were done by the US Computer Emergency Response Team, which normally means that the vulnerabilities are under active exploitation. I will file an SA once I'm done catching up on mail.

The rest of the release notes for Qt can be found at https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.7.2/release-note.md

comment:5 by Douglas R. Reno, 9 months ago

SA-12.1-070 issued

Note: See TracTickets for help on using tickets.