#21672 closed enhancement (fixed)

qt6-6.9.1 qtwebengine-6.9.1

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description


Change History (10)

comment:1 by Douglas R. Reno, 16 months ago

At the moment release notes are not available. I'll check again in the morning.

comment:2 by martyj19, 16 months ago

There is a new warning in qtwebengine

WARNING: Qt WebEngine And Qt Pdf SBOM generation will be skipped due to missing dependencies. Required Python dependencies not found:  spdx_tools.spdx.clitools.pyspdxtools

and in fact there is no .spdx file for qtwebengine in the sbom subdirectory.

You can supply the Python module spdx-tools (I didn't test this) or salt

-DQT_GENERATE_SBOM=OFF

through all of the Qt builds to turn off this subdirectory entirely.

Last edited 16 months ago by martyj19 (previous) (diff)

comment:3 by Douglas R. Reno, 16 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

in reply to:  2 comment:4 by Douglas R. Reno, 16 months ago

Replying to martyj19:

There is a new warning in qtwebengine

WARNING: Qt WebEngine And Qt Pdf SBOM generation will be skipped due to missing dependencies. Required Python dependencies not found:  spdx_tools.spdx.clitools.pyspdxtools

and in fact there is no .spdx file for qtwebengine in the sbom subdirectory.

You can supply the Python module spdx-tools (I didn't test this) or salt

-DQT_GENERATE_SBOM=OFF

through all of the Qt builds to turn off this subdirectory entirely.

I think adding in -DQT_GENERATE_SBOM=OFF is probably the best approach here and it's what I'll put in for now :) thank you for bringing it up!

comment:5 by Douglas R. Reno, 16 months ago

Priority: normal → high

Qt itself has no security fixes, but QtWebEngine has it's normal set of series Chromium ones...

  • CVE-2025-1921: Inappropriate implementation in Media Stream (Medium), allows attackers to retrieve information about a peripheral via a crafted HTML page
  • CVE-2025-1919: Out of bounds read in Media (High), RCE
  • CVE-2025-1918: Out of bounds read in PDFium (High), RCE via crafted PDF file
  • CVE-2025-1916: Use after free in Profiles (High), allows users to install malicious extensions that execute arbitrary code
  • CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools (High), allows an extension to bypass file restrictions
  • CVE-2025-2136: Use after free in Inspector (High), RCE
  • CVE-2025-1920: Type Confusion in V8 (High), RCE
  • CVE-2025-24855: use after free in libxslt (High), RCE - note that BLFS is not impacted if you have already installed libxslt via SA-12.3-004
  • CVE-2024-55549: use after free in libxslt (High), RCE - note that BLFS is not impacted if you have already installed libxslt via SA-12.3-004
  • CVE-2025-3071: Inappropriate implementation in Navigations (Medium), same origin policy bypass
  • CVE-2025-3069: Inappropriate implementation in Extensions (High), remotely exploitable privilege escalation
  • CVE-2025-2783: Incorrect handle provided in unspecified circumstances in Mojo (High), remotely exploitable sandbox escape
  • CVE-2025-3619: Heap buffer overflow in Codecs (Critical), RCE
  • CVE-2025-4052: Inappropriate implementation in DevTools (Critical), access control bypass
  • CVE-2025-4051: Insufficient data validation in DevTools (Medium), access control bypass
  • CVE-2025-4096: Heap buffer overflow in HTML (High), RCE
  • CVE-2025-3277: Integer overflow in SQLite (Medium), arbitrary code execution
  • CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo (High), RCE
  • CVE-2025-4664: Insufficient policy enforcement in Loader (Medium), cross origin information leakage

comment:6 by Douglas R. Reno, 16 months ago

The protobuf patch has been applied upstream!

comment:7 by Douglas R. Reno, 16 months ago

This protobuf problem is getting really annoying.

Most of the patch has been applied upstream, but evidently something is still wrong because we're still getting:

CMake Error at /usr/lib/cmake/protobuf/protobuf-targets.cmake:132 (message):
  The imported target "protobuf::libupb" references the file

     "/usr/lib/libupb.a"

  but this file does not exist.  Possible reasons include:

  * The file was deleted, renamed, or moved to another location.

  * An install or uninstall procedure did not complete successfully.

  * The installation package was faulty and contained

     "/usr/lib/cmake/protobuf/protobuf-targets.cmake"

  but not all the files it references.

If I remember correctly Pierre was the one who discovered the problem and had resolved it. I'm going to reinstall Protobuf on my machine with the static library for now, but I would like someone else to look into this.

comment:8 by Douglas R. Reno, 16 months ago

In QtWebEngine though, the patch as well as the pipewire fix have been applied

in reply to:  7 comment:9 by Joe Locash, 16 months ago

Replying to Douglas R. Reno:

If I remember correctly Pierre was the one who discovered the problem and had resolved it. I'm going to reinstall Protobuf on my machine with the static library for now, but I would like someone else to look into this.

I don't normally build qtwebengine, but it built fine for me. I don't remove libupb.a when building protobuf. IIRC that is what Piere suggested when building with protobuf > 30. Thread: ​https://lists.linuxfromscratch.org/sympa/arc/blfs-dev/2025-05/msg00043.html

comment:10 by Douglas R. Reno, 16 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 1ecd69139a2a076b97846e544c6a8154ad470fe9

SA-12.3-046 issued

Note: See TracTickets for help on using tickets.