Opened 6 months ago

Closed 6 months ago

#23019 closed enhancement (fixed)

qt6-6.11.0 qtwebengine-6.11.0

Reported by: Bruce Dubbs Owned by: zeckma
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: critical Keywords:
Cc:

Description

New minor version.

Change History (10)

comment:1 by Bruce Dubbs, 6 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 6 months ago

qt6 updated at commit e3983103e5.

comment:3 by Bruce Dubbs, 6 months ago

Fixed at commit 4953dade53.

Leaving open for security advisory.

comment:4 by Bruce Dubbs, 6 months ago

Severity: normal → critical

comment:5 by zeckma, 6 months ago

Priority: normal → high

comment:6 by zeckma, 6 months ago

Owner: changed from Bruce Dubbs to zeckma
Status: assigned → new

I'll handle the SA.

comment:7 by zeckma, 6 months ago

Status: new → assigned

comment:8 by Douglas R. Reno, 6 months ago

QtWebEngine 6.11.0 security fixes:

  • CVE-2025-14766 – 8.8 High, Out of bounds read and write in V8 (RCE)
  • CVE-2026-1504 – 6.5 Medium, Inappropriate implementation in Background Fetch API (cross-origin data exfiltration)
  • CVE-2026-1220 – 9.8 Critical, Race in V8 (RCE)
  • CVE-2026-0908 – 8.8 High, Use after free in ANGLE (RCE)
  • CVE-2026-0905 – 9.8 Critical, Insufficient policy enforcement in Network (sensitive information disclosure via a network log file)
  • CVE-2026-0902 – 8.8 High, Inappropriate implementation in V8 (RCE)
  • CVE-2026-0899 – 8.8 High, Out of bounds memory access in V8 (RCE)
  • CVE-2026-0628 – 8.8 High, Insufficient policy enforcement in WebView (malicious extension can inject scripts or HTML into privileged pages)
  • CVE-2026-1861 – 8.8 High, Heap buffer overflow in libvpx (RCE)
  • CVE-2026-2441 – 8.8 High, Use after free in CSS (RCE within sandbox)
  • CVE-2026-2320 – 6.5 Medium, Inappropriate implementation in File input (UI spoofing)
  • CVE-2026-2319 – 7.5 High, Race in DevTools (object corruption via a malicious file with malicious extensions installed)
  • CVE-2026-2317 – 6.5 Medium, Inappropriate implementation in Animation (cross-origin data leakage)
  • CVE-2026-2316 – 6.5 Medium, Insufficient policy enforcement in Frames (UI spoofing)
  • CVE-2026-2314 – 8.8 High, Heap buffer overflow in Codecs (RCE)
  • CVE-2026-2315 – 8.8 High, Inappropriate implementation in WebGPU (RCE)
  • CVE-2026-2650 – 8.8 High, Heap buffer overflow in Media (RCE)
  • CVE-2026-2649 – 8.8 High, Integer overflow in V8 (RCE)
  • CVE-2026-2648 – 8.8 High, Heap buffer overflow in PDFium (RCE)
  • CVE-2026-3063 – 8.8 High, Inappropriate implementation in DevTools (malicious extensions can inject scripts or HTML into privileged pages)
  • CVE-2026-3062 – 9.8 Critical, Out of bounds read and write in Tint (RCE)
  • CVE-2026-3061 – 9.1 Critical, Out of bounds read in Media (Trivial RCE)
  • CVE-2026-3537 – 8.8 High, Object lifecycle issue in PowerVR (RCE)
  • CVE-2026-3545 – 9.6 Critical, Insufficient data validation in Navigation (SANDBOX ESCAPE)
  • CVE-2026-3544 – 8.8 High, Heap buffer overflow in WebCodecs (RCE)
  • CVE-2026-3543 – 8.8 High, Inappropriate implementation in V8 (RCE)
  • CVE-2026-3542 – 8.8 High, Inappropriate implementation in WebAssembly (RCE)
  • CVE-2026-3541 – 8.8 High, Inappropriate implementation in CSS (RCE)
  • CVE-2026-3540 – 8.8 High, Inappropriate implementation in WebAudio (RCE)
  • CVE-2026-3539 – 8.8 High, Object lifecycle issue in DevTools (malicious extension allows for RCE)
  • CVE-2026-3538 – 8.8 High, Integer overflow in Skia (RCE)
  • CVE-2026-3536 – 8.8 High, Integer overflow in ANGLE (RCE)
  • CVE-2026-3910 – 8.8 High, Inappropriate implementation in V8 (RCE). Known to be actively exploited by a threat actor. US Government suggests users apply patches by 3/27 see ​https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3910
  • CVE-2026-3909 – 8.8 High, Out of bounds write in Skia (RCE). Known to be actively exploited by a threat actor. US Government suggests users apply patches by 3/27 see ​https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3909
  • CVE-2026-3919 – 8.8 High, Use after free in Extensions (RCE via malicious extension).
  • CVE-2026-3942 – 4.3 Medium, Incorrect security UI in PictureInPicture (UI spoofing)
  • CVE-2026-3941 – 4.3 Medium, Insufficient policy enforcement in DevTools (remote attacker can bypass navigation restrictions)
  • CVE-2026-3940 – 5.3 Medium, Insufficient policy enforcement in DevTools (navigation restriction bypass)
  • CVE-2026-3938 – 6.5 Medium, Insufficient policy enforcement in Clipboard (cross-origin data exfiltration)
  • CVE-2026-3934 – 6.5 Medium, Insufficient policy enforcement in ChromeDriver (same origin policy bypass)
  • CVE-2026-3931 – 8.8 High, Heap buffer overflow in Skia (RCE)
  • CVE-2026-3929 – 3.1 Low, Side-channel information leakage in ResourceTiming (cross-origin data exfiltration)
  • CVE-2026-3926 – 8.8 High, Out of bounds read in V8 (RCE)
  • CVE-2026-3924 – 8.8 High, Use After Free in WindowDialog (SANDBOX ESCAPE)
  • CVE-2026-3923 – 8.8 High, Use after free in WebMIDI (RCE)
  • CVE-2026-3922 – 8.8 High, Use after free in MediaStream (RCE)
  • CVE-2026-3921 – 8.8 High, Use after free in TextEncoding (RCE)

comment:9 by Douglas R. Reno, 6 months ago

The CVEs from the Qt 6.11 release notes (see ​https://code.qt.io/cgit/qt/qtreleasenotes.git/about/qt/6.11.0/release-note.md) were fixed in 6.9 and 6.10.x point releases, and we are thus safe from those four.

comment:10 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: assigned → closed

SA-13.0-026 issued

Note: See TracTickets for help on using tickets.