Opened 7 months ago

Closed 6 months ago

#21858 closed enhancement (fixed)

Fix CVE-2025-5992 in Qt6 and also backport patches to fix crashes with KDE Plasma 6.4

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: elevated Milestone: 12.4
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

While I was looking around on my Gentoo system earlier I noticed they have a new security patch. There's a blog post at https://www.qt.io/blog/security-advisory-recently-reported-denial-of-service-issue-in-qcolortransfergenericfunction-impacts-qt about it.

I have tested the patch from https://download.qt.io/official_releases/qt/6.9/CVE-2025-5992-qtbase-6.9.patch and it works well on one of my systems.

In addition to fixing this we'll want to also backport the following fixes:

These came from https://gitlab.archlinux.org/archlinux/packaging/packages/qt6-base/-/commits/main with a pointer to https://gitlab.archlinux.org/archlinux/packaging/packages/qt6-base/-/merge_requests/2

Change History (5)

comment:1 by Douglas R. Reno, 7 months ago

Note that the next release of Qt6 will be after we go into package freeze, so we'll want to fix these now

comment:2 by Douglas R. Reno, 7 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: newassigned

comment:4 by Douglas R. Reno, 6 months ago

SA-12.3-083 issued

comment:5 by Douglas R. Reno, 6 months ago

Resolution: fixed
Status: assignedclosed
Note: See TracTickets for help on using tickets.