Opened 8 months ago
Closed 8 months ago
#22713 closed enhancement (fixed)
qt6-6.10.2 qtwebengine-6.10.2
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point versions.
Change History (7)
comment:1 by , 8 months ago
| Milestone: | 12.5 → 13.0 |
|---|
comment:2 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 8 months ago
Release notes are at https://github.com/qt/qtreleasenotes/blob/dev/qt/6.10.2/release-note.md
comment:4 by , 8 months ago
This version fixes the qtdeclaritive problem that was fixed earlier by a patch.
comment:5 by , 8 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at commits
d07d67406b Update to qt6-6.10.2 and qtwebengine-6.10.2. 21a658970f Update to openldap-2.6.12. abcafbecbb Update to bluefish-2.4.0. d0f69fae93 Update to git-2.53.0.
comment:6 by , 8 months ago
| Priority: | normal → high |
|---|---|
| Resolution: | fixed |
| Status: | closed → reopened |
Security fixes are present here for both the base Qt and QtWebEngine...
For the base qt, we have:
- CVE-2025-14576 in qtdeclarative
For QtWebEngine, we have:
- CVE-2025-13042: Inappropriate implementation in V8 (8.8 High, RCE)
- CVE-2025-14174: Out of bounds memory access in ANGLE (8.8 High, RCE)
- CVE-2025-13639: Inappropriate implementation in WebRTC (8.1 High, arbitrary filesystem read/write)
- CVE-2025-13638: Use after free in Media Stream (8.8 High, RCE)
- CVE-2025-13721: Race in v8 (7.5 High, RCE)
- CVE-2025-13720: Bad cast in Loader (8.8 High, RCE)
- CVE-2025-13634: Inappropriate implementation in Downloads (4.4 Medium, MOTW bypass)
- CVE-2025-13224: Type Confusion in V8 (8.8 High, RCE)
- CVE-2025-141765: Unknown
- CVE-2026-0899: Out of bounds memory access in V8 (8.8 High, RCE)
- CVE-2026-0905: Insufficient policy enforcement in Network (sensitive information exfiltration via remote accessing of the network log file, 9.8 Critical)
- CVE-2026-0908: Use after free in ANGLE (8.8 High, RCE)
- CVE-2026-1220: Unknown
Reopening for a security advisory
Note:
See TracTickets
for help on using tickets.

Milestone renamed