Opened 16 months ago
Closed 16 months ago
#21672 closed enhancement (fixed)
qt6-6.9.1 qtwebengine-6.9.1
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Change History (10)
comment:1 by , 16 months ago
follow-up: 4 comment:2 by , 16 months ago
There is a new warning in qtwebengine
WARNING: Qt WebEngine And Qt Pdf SBOM generation will be skipped due to missing dependencies. Required Python dependencies not found: spdx_tools.spdx.clitools.pyspdxtools
and in fact there is no .spdx file for qtwebengine in the sbom subdirectory.
You can supply the Python module spdx-tools (I didn't test this) or salt
-DQT_GENERATE_SBOM=OFF
through all of the Qt builds to turn off this subdirectory entirely.
comment:3 by , 16 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 16 months ago
Replying to martyj19:
There is a new warning in qtwebengine
WARNING: Qt WebEngine And Qt Pdf SBOM generation will be skipped due to missing dependencies. Required Python dependencies not found: spdx_tools.spdx.clitools.pyspdxtoolsand in fact there is no .spdx file for qtwebengine in the sbom subdirectory.
You can supply the Python module spdx-tools (I didn't test this) or salt
-DQT_GENERATE_SBOM=OFFthrough all of the Qt builds to turn off this subdirectory entirely.
I think adding in -DQT_GENERATE_SBOM=OFF is probably the best approach here and it's what I'll put in for now :) thank you for bringing it up!
comment:5 by , 16 months ago
| Priority: | normal → high |
|---|
Qt itself has no security fixes, but QtWebEngine has it's normal set of series Chromium ones...
- CVE-2025-1921: Inappropriate implementation in Media Stream (Medium), allows attackers to retrieve information about a peripheral via a crafted HTML page
- CVE-2025-1919: Out of bounds read in Media (High), RCE
- CVE-2025-1918: Out of bounds read in PDFium (High), RCE via crafted PDF file
- CVE-2025-1916: Use after free in Profiles (High), allows users to install malicious extensions that execute arbitrary code
- CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools (High), allows an extension to bypass file restrictions
- CVE-2025-2136: Use after free in Inspector (High), RCE
- CVE-2025-1920: Type Confusion in V8 (High), RCE
- CVE-2025-24855: use after free in libxslt (High), RCE - note that BLFS is not impacted if you have already installed libxslt via SA-12.3-004
- CVE-2024-55549: use after free in libxslt (High), RCE - note that BLFS is not impacted if you have already installed libxslt via SA-12.3-004
- CVE-2025-3071: Inappropriate implementation in Navigations (Medium), same origin policy bypass
- CVE-2025-3069: Inappropriate implementation in Extensions (High), remotely exploitable privilege escalation
- CVE-2025-2783: Incorrect handle provided in unspecified circumstances in Mojo (High), remotely exploitable sandbox escape
- CVE-2025-3619: Heap buffer overflow in Codecs (Critical), RCE
- CVE-2025-4052: Inappropriate implementation in DevTools (Critical), access control bypass
- CVE-2025-4051: Insufficient data validation in DevTools (Medium), access control bypass
- CVE-2025-4096: Heap buffer overflow in HTML (High), RCE
- CVE-2025-3277: Integer overflow in SQLite (Medium), arbitrary code execution
- CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo (High), RCE
- CVE-2025-4664: Insufficient policy enforcement in Loader (Medium), cross origin information leakage
follow-up: 9 comment:7 by , 16 months ago
This protobuf problem is getting really annoying.
Most of the patch has been applied upstream, but evidently something is still wrong because we're still getting:
CMake Error at /usr/lib/cmake/protobuf/protobuf-targets.cmake:132 (message):
The imported target "protobuf::libupb" references the file
"/usr/lib/libupb.a"
but this file does not exist. Possible reasons include:
* The file was deleted, renamed, or moved to another location.
* An install or uninstall procedure did not complete successfully.
* The installation package was faulty and contained
"/usr/lib/cmake/protobuf/protobuf-targets.cmake"
but not all the files it references.
If I remember correctly Pierre was the one who discovered the problem and had resolved it. I'm going to reinstall Protobuf on my machine with the static library for now, but I would like someone else to look into this.
comment:8 by , 16 months ago
In QtWebEngine though, the patch as well as the pipewire fix have been applied
comment:9 by , 16 months ago
Replying to Douglas R. Reno:
If I remember correctly Pierre was the one who discovered the problem and had resolved it. I'm going to reinstall Protobuf on my machine with the static library for now, but I would like someone else to look into this.
I don't normally build qtwebengine, but it built fine for me. I don't remove libupb.a when building protobuf. IIRC that is what Piere suggested when building with protobuf > 30. Thread: https://lists.linuxfromscratch.org/sympa/arc/blfs-dev/2025-05/msg00043.html
comment:10 by , 16 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 1ecd69139a2a076b97846e544c6a8154ad470fe9
SA-12.3-046 issued

At the moment release notes are not available. I'll check again in the morning.