Opened 11 months ago

Closed 11 months ago

Last modified 8 months ago

#22372 closed enhancement (fixed)

qt6 qtwebengine 6.10.1

Reported by: Joe Locash Owned by: Bruce Dubbs
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: critical Keywords:
Cc:

Description

When grabbing a submodule I needed for qt I noticed 2 patches for qtdeclarative in the 6.10 directory (​https://download.qt.io/official_releases/qt/6.10/). They are: CVE-2025-12385-qtdeclarative-6.10-0002.diff and CVE-2025-12385-qtdeclarative-6.10-0001.diff and they were made available yesterday. There is no information about that CVE yet but I don't think Qt would tag and publish them with CVE in the filename unless there was an issue. 0002.diff needs to be applied before 00 01.diff.

Change History (6)

comment:1 by Douglas R. Reno, 11 months ago

I'll take care of this later, but I'm going to want more details on the CVE first so I know what to say in the advisory. I'll keep checking every few hours, I can't find any information anywhere yet other than the patch existing

comment:2 by Douglas R. Reno, 11 months ago

Priority: elevated → high
Severity: normal → critical
Summary: Fix CVE-2025-12385 in qtdeclarative → qt6 qtwebengine 6.10.1

The release notes for Qt 6.10.1 can be found here: ​https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.10.1/release-note.md

No details yet on CVE-2025-12385, but given what's going on with QtWebEngine, let's continue with this update as is. To me it appears to be a problem which allows for denial of service and possibly other impacts, at least based off the two patches that were released for 6.10.0.

QtWebEngine CVEs

  • CVE-2025-6021 - 7.5 High, stack based buffer overflow from libxml2. For most of our users this shouldn't affect anything since we build libxml2 with ICU now, and thus it doesn't use the bundled version - but let's still document it anyway.
  • CVE-2025-12036 - 8.8 High, Out of bounds memory access in V8 via HTML page (RCE)
  • CVE-2025-12726 - 7.5 High, Inappropriate implementation in Views (Remotely exploitable privilege escalation)
  • CVE-2025-12432 - 8.8 High, Race in V8 (heap corruption via HTML page)
  • CVE-2025-12429 - 8.8 High, Inappropriate implementation in V8 (allows remote attackers to read/write files from the filesystem)
  • CVE-2025-12438 - 8.8 High, Use after free in Ozone (allows remote attackers to perform object corruption *specifically* on Linux)
  • CVE-2025-12441 - 4.3 Medium, Out of bounds read in V8 (remotely exploitable DoS)
  • CVE-2025-12433 - 4.3 Medium, Inappropriate implementation in V8 (remotely exploitable DoS)
  • CVE-2025-12443 - 4.3 Medium, Out of bounds read in WebXR (remotely exploitable DoS)
  • CVE-2025-24928 - 7.8 High, stack buffer overflow in bundled libxml2 (RCE)
  • CVE-2025-6021 - 7.5 High, stack buffer overflow in bundled libxml2 (RCE)
  • CVE-2025-11756 - 8.8 High, Use after free in Safe Browsing (RCE)
  • CVE-2025-11460 - 8.8 High, Use after free in Storage (remote code execution via crafted video file)
  • CVE-2025-11458 - 8.8 High, Heap buffer overflow in Sync (RCE)
  • CVE-2025-11216 - 6.3 Medium, Inappropriate implementation in Storage (domain spoofing via crafted video file)
  • CVE-2025-11207 - 6.5 Medium, Side-channel information leakage in Storage (remotely exploitable read/write access to filesystem via HTML page)
  • CVE-2025-11219 - 3.1 Low, Use after free in V8 (DoS)
  • CVE-2025-6965 - 9.8 Critical, memory corruption via SQLite (RCE)
  • CVE-2025-11206 - 7.1 High, Heap buffer overflow in Video (Sandbox Escape)
  • CVE-2025-13042 - 8.8 High, Inappropriate implementation in V8 (RCE)
  • CVE-2025-13223 - 8.8 High, Type Confusion in V8 (RCE). Actively exploited, see news articles such as ​https://thehackernews.com/2025/11/google-issues-security-fix-for-actively.html and ​https://www.cisa.gov/news-events/alerts/2025/11/19/cisa-adds-one-known-exploited-vulnerability-catalog

Note that the sandbox escape significantly amplifies the impact of the other vulnerabilities in this list, giving them much more access to the system**

comment:3 by Bruce Dubbs, 11 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:4 by Bruce Dubbs, 11 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

337bbef00d Update to poppler-25.11.0.
214c6f3826 Update to qt6 and qtwebengine 6.10.1.

comment:5 by zeckma, 10 months ago

SA-12.4-035 filed. QtSVG security fixes were included in the SA. It wasn't too much trouble but it'd be appreciated if tickets like these weren't closed until SAs were filed and pushed to www.git. Thanks!

comment:6 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.