Opened 2 weeks ago
Closed 13 days ago
#21378 closed enhancement (fixed)
qt6-6.9.0 qtwebengine-6.9.0
Reported by: | Bruce Dubbs | Owned by: | blfs-book |
---|---|---|---|
Priority: | elevated | Milestone: | 12.4 |
Component: | BOOK | Version: | git |
Severity: | normal | Keywords: | |
Cc: |
Description ¶
New minor version. We just did a point version 5 days ago, :(
Change History (6)
comment:1 by , 2 weeks ago
Priority: | normal → elevated |
---|
comment:2 by , 2 weeks ago
I think the CVEs are all for older versions of Qt before 6.8.3 which we have in the book now.
comment:3 by , 2 weeks ago
CVE-2025-23050 and CVE-2024-39936 were fixed in prior updates along the 6.8.x line, but CVE-2025-30348 appears to be new. NVD mentions that it was fixed in 6.8.0, but I think that might be incorrect as there is no mention of that vulnerability in the release notes for 6.8.0, nor on the Qt Security website. https://wiki.qt.io/List_of_known_vulnerabilities_in_Qt_products
comment:4 by , 2 weeks ago
Further research shows that the bug number (QTBUG-127549) was resolved in 6.8.0, but it was not assigned a CVE at the time:
Qt 6.8.0 release notes: https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.8.0/release-note.md
Qt Code Review: https://codereview.qt-project.org/c/qt/qtbase/+/586374
Qt Bug Report: https://bugreports.qt.io/browse/QTBUG-127549
I'm going to go check QtWebEngine now. If no new CVEs are fixed there, I will downgrade this back to normal
comment:5 by , 2 weeks ago
QtWebEngine CVEs
- CVE-2025-0434: Out of bounds memory access in V8 (High) - RCE
- CVE-2025-0445: Use after free in V8 (High) - RCE
- CVE-2025-0995: Use after free in V8 (High) - RCE
There was a lot of overlap with 6.8.3 (which is a very good thing given one of the 0days fixed in 6.8.3/WebKitGTK 2.48.0)
Release notes are at https://www.qt.io/blog/qt-6.9-released and https://github.com/qt/qtreleasenotes/blob/dev/qt/6.9.0/release-note.md
Three CVEs: