Opened 18 months ago

Closed 18 months ago

Last modified 17 months ago

#21378 closed enhancement (fixed)

qt6-6.9.0 qtwebengine-6.9.0

Reported by: Bruce Dubbs Owned by: blfs-book
Priority: elevated Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version. We just did a point version 5 days ago, :(

Change History (8)

comment:1 by Bruce Dubbs, 18 months ago

Priority: normal → elevated

Release notes are at ​https://www.qt.io/blog/qt-6.9-released and ​https://github.com/qt/qtreleasenotes/blob/dev/qt/6.9.0/release-note.md

Three CVEs:

CVE-2025-30348 in qtbase
CVE-2025-23050 in qtconnectivity
CVE-2024-39936 in qtbase

comment:2 by Bruce Dubbs, 18 months ago

I think the CVEs are all for older versions of Qt before 6.8.3 which we have in the book now.

comment:3 by Douglas R. Reno, 18 months ago

CVE-2025-23050 and CVE-2024-39936 were fixed in prior updates along the 6.8.x line, but CVE-2025-30348 appears to be new. NVD mentions that it was fixed in 6.8.0, but I think that might be incorrect as there is no mention of that vulnerability in the release notes for 6.8.0, nor on the Qt Security website. ​https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products

comment:4 by Douglas R. Reno, 18 months ago

Further research shows that the bug number (QTBUG-127549) was resolved in 6.8.0, but it was not assigned a CVE at the time:

Qt 6.8.0 release notes: ​https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.8.0/release-note.md

Qt Code Review: ​https://codereview.qt-project.org/c/qt/qtbase/+/586374

Qt Bug Report: ​https://bugreports.qt.io/browse/QTBUG-127549

I'm going to go check QtWebEngine now. If no new CVEs are fixed there, I will downgrade this back to normal

comment:5 by Douglas R. Reno, 18 months ago

QtWebEngine CVEs

  • CVE-2025-0434: Out of bounds memory access in V8 (High) - RCE
  • CVE-2025-0445: Use after free in V8 (High) - RCE
  • CVE-2025-0995: Use after free in V8 (High) - RCE

There was a lot of overlap with 6.8.3 (which is a very good thing given one of the 0days fixed in 6.8.3/WebKitGTK 2.48.0)

comment:6 by Bruce Dubbs, 18 months ago

Resolution: → fixed
Status: new → closed

Fixed at commit 910063fbcd.

comment:7 by Douglas R. Reno, 17 months ago

There was another CVE fixed here that wasn't documented until later - CVE-2025-3512 (which is rated as Low). It's in qtbase and is a buffer overflow when processing a malformed Markdown document. ​https://www.qt.io/blog/security-advisory-qtextmarkdownimporter-hbo

I've filed SA-12.3-011 for it, but documented the caveats of upgrading. In particular, you need to rebuild qca and qcoro as well as Plasma, layer-shell-qt (if you have the minimum LXQt set), and libportal if they are installed due to their usage of private API that has changed.

comment:8 by Douglas R. Reno, 17 months ago

SA-12.3-012 issued for QtWebEngine

Note: See TracTickets for help on using tickets.