Opened 8 months ago

Closed 8 months ago

#22713 closed enhancement (fixed)

qt6-6.10.2 qtwebengine-6.10.2

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point versions.

Change History (7)

comment:1 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

comment:2 by Bruce Dubbs, 8 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:4 by Bruce Dubbs, 8 months ago

This version fixes the qtdeclaritive problem that was fixed earlier by a patch.

comment:5 by Bruce Dubbs, 8 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

d07d67406b Update to qt6-6.10.2 and qtwebengine-6.10.2.
21a658970f Update to openldap-2.6.12.
abcafbecbb Update to bluefish-2.4.0.
d0f69fae93 Update to git-2.53.0.

comment:6 by Douglas R. Reno, 8 months ago

Priority: normal → high
Resolution: fixed
Status: closed → reopened

Security fixes are present here for both the base Qt and QtWebEngine...

For the base qt, we have:

  • CVE-2025-14576 in qtdeclarative

For QtWebEngine, we have:

  • CVE-2025-13042: Inappropriate implementation in V8 (8.8 High, RCE)
  • CVE-2025-14174: Out of bounds memory access in ANGLE (8.8 High, RCE)
  • CVE-2025-13639: Inappropriate implementation in WebRTC (8.1 High, arbitrary filesystem read/write)
  • CVE-2025-13638: Use after free in Media Stream (8.8 High, RCE)
  • CVE-2025-13721: Race in v8 (7.5 High, RCE)
  • CVE-2025-13720: Bad cast in Loader (8.8 High, RCE)
  • CVE-2025-13634: Inappropriate implementation in Downloads (4.4 Medium, MOTW bypass)
  • CVE-2025-13224: Type Confusion in V8 (8.8 High, RCE)
  • CVE-2025-141765: Unknown
  • CVE-2026-0899: Out of bounds memory access in V8 (8.8 High, RCE)
  • CVE-2026-0905: Insufficient policy enforcement in Network (sensitive information exfiltration via remote accessing of the network log file, 9.8 Critical)
  • CVE-2026-0908: Use after free in ANGLE (8.8 High, RCE)
  • CVE-2026-1220: Unknown

Reopening for a security advisory

comment:7 by Douglas R. Reno, 8 months ago

Resolution: → fixed
Status: reopened → closed

SA-12.4-085 issued

Note: See TracTickets for help on using tickets.