Opened 5 months ago

Closed 4 months ago

#23291 closed enhancement (fixed)

qt6-6.11.1 qtwebengine-6.11.1

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: critical Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by Bruce Dubbs, 5 months ago

Release notes are at ​https://github.com/qt/qtreleasenotes/blob/dev/qt/6.11.1/release-note.md

qt6 still needs an OpenSSL4 patch and qtopcua (not needed by BLFS) has build errors and can be omitted.

qtwebengine has bot been tested yet.

comment:2 by Douglas R. Reno, 5 months ago

Priority: normal → high

Qt6 is vulnerable to CVE-2026-6210, which is a type confusion vulnerability rated as 8.7 High in QtSVG. It looks to be easily remotely exploitable.

Triaging QtWebEngine now...

comment:3 by Douglas R. Reno, 5 months ago

Severity: normal → critical

This was extremely painful to write because of the sheer amount... took a solid hour and a half to gather the details!

  • CVE-2026-4454: Use after free in Network: 8.8 High, RCE
  • CVE-2026-4455: Heap buffer overflow in PDFium: 8.8 High, RCE via crafted PDF
  • CVE-2026-4457: Type Confusion in V8: 8.8 High, RCE
  • CVE-2026-4458: Use after free in Extensions: 8.8 High, RCE via crafted extension
  • CVE-2026-4453: Integer overflow in Dawn: 4.3 Medium, cross origin data exfiltration
  • CVE-2026-4452: Integer overflow in ANGLE: 8.8 High, RCE
  • CVE-2026-4450: Out of bounds write in V8: 8.8 High, RCE
  • CVE-2026-4459: Out of bounds read and write in WebAudio: 8.8 High, RCE
  • CVE-2026-4464: Integer overflow in ANGLE: 8.8 High, RCE
  • CVE-2026-4451: Insufficient validation of untrusted input in Navigation: 8.8 High, Sandbox Escape
  • CVE-2026-4449: Use after free in Blink: 8.8 High, RCE
  • CVE-2026-4448: Heap buffer overflow in ANGLE: 8.8 High, RCE
  • CVE-2026-4446: Use after free in WebRTC: 8.8 High, RCE
  • CVE-2026-4445: Use after free in WebRTC: 8.8 High, RCE
  • CVE-2026-4444: Stack buffer overflow in WebRTC: 8.8 High, RCE
  • CVE-2026-4443: Heap buffer overflow in WebAudio: 8.8 High, arbitrary code execution in a sandbox
  • CVE-2026-4442: Heap buffer overflow in CSS: 8.8 High, RCE
  • CVE-2026-4459: Out of bounds read and write in WebAudio: 8.8 High, RCE
  • CVE-2026-4460: Out of bounds read in Skia: 8.8 High, RCE
  • CVE-2026-4462: Out of bounds read in Blink: 8.8 High, RCE
  • CVE-2026-4463: Heap buffer overflow in WebRTC: 8.8 High, RCE
  • CVE-2026-4440: Out of bounds read and write in WebGL: 8.8 High, remote attacker can read/write files from a user’s filesystem via crafted HTML
  • CVE-2026-4441: Use after free in Base: 8.8 High, RCE
  • CVE-2026-4677: Inappropriate implementation in WebAudio: 8.8 High, RCE
  • CVE-2026-4679: Integer overflow in Fonts: 8.8 High, RCE
  • CVE-2026-4675: Heap buffer overflow in WebGL: 8.8 High, RCE
  • CVE-2026-4674: Out of bounds read in CSS: 8.8 High, RCE
  • CVE-2026-5283: Inappropriate implementation in ANGLE: 6.5 Medium, cross origin data exfiltration
  • CVE-2026-5282: Out of bounds read in WebCodecs: 8.1 High, RCE
  • CVE-2026-5281: Use after free in Dawn: 8.8 High, arbitrary code execution. *KNOWN EXPLOITED AS OF 04/01/2026*
  • CVE-2026-5280: Use after free in WebCodecs: 8.8 High, arbitrary code execution
  • CVE-2026-5279: Object corruption in V8: 8.8 High, arbitrary code execution
  • CVE-2026-5277: Integer overflow in ANGLE. 7.5 High, RCE
  • CVE-2026-5276: Insufficient policy enforcement in WebUSB: 6.5 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
  • CVE-2026-5275: Heap buffer overflow in ANGLE: 8.8 High, RCE
  • CVE-2026-5274: Integer overflow in Codecs: 8.8 High, remote attacker can read/write files from a user’s filesystem via crafted HTML
  • CVE-2026-5272: Heap buffer overflow in GPU: 8.8 High, RCE
  • CVE-2026-5273: Use after free in CSS: 6.3 Medium, arbitrary code execution inside of a sandbox
  • CVE-2026-5292: Out of bounds read in WebCodecs: 8.8 High, RCE
  • CVE-2026-5291: Inappropriate implementation in WebGL: 6.5 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
  • CVE-2026-5290: Use after free in Compositing: 9.6 Critical, sandbox escape
  • CVE-2026-5289: Use after free in Navigation: 9.6 Critical, sandbox escape
  • CVE-2026-5287: Use after free in PDF: 8.8 High, arbitrary code execution in a sandbox via a crafted PDF file
  • CVE-2026-5285: Use after free in WebGL: 8.8 High, arbitrary code execution in a sandbox
  • CVE-2026-5284: Use after free in Dawn: 7.5 High, RCE
  • CVE-2026-5889: Cryptographic Flaw in PDFium: 4.3 Medium, allows attackers to brute force sensitive information out of encrypted PDF files
  • CVE-2026-5890: Race in WebCodecs: 5.3 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
  • CVE-2026-5888: Uninitialized Use in WebCodecs: 6.5 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
  • CVE-2026-5899: Incorrect security UI in History Navigation: 6.1 Medium, remote attacker who convinced a user to engage in specific UI gestures can inject arbitrary scripts or HTML (UXSS) via a crafted HTML page
  • CVE-2026-5900: Policy bypass in Downloads: 4.3 Medium, remote attacker can allow multiple downloads to happen simultaneously via a crafted HTML page
  • CVE-2026-5896: Policy bypass in Audio: 6.1 Medium, remote attacker who convinced a user to engage in specific UI gestures can bypass sandbox download restrictions via a crafted HTML page
  • CVE-2026-5919: Insufficient validation of untrusted input in WebSockets: 6.5 Medium, same origin policy bypass
  • CVE-2026-5903: Policy bypass in IframeSandbox: 6.5 Medium, navigation restrictions bypass
  • CVE-2026-5904: Use after free in V8: 8.8 High, malicious extension can cause RCE
  • CVE-2026-5907: Insufficient data validation in Media: 8.1 High, RCE via crafted video file
  • CVE-2026-5908: Integer overflow in Media: 8.8 High, RCE via crafted video file
  • CVE-2026-5909: Integer overflow in Media: 8.8 High, RCE via crafted video file
  • CVE-2026-5910: Integer overflow in Media: 8.8 High, RCE via crafted video file
  • CVE-2026-5912: Integer overflow in WebRTC: 8.8 High, RCE
  • CVE-2026-5918: Inappropriate implementation in Navigation: 4.3 Medium, cross origin data exfiltration
  • CVE-2026-5915: Insufficient validation of untrusted input in WebML: 8.1 High, RCE
  • CVE-2026-5914: Type Confusion in CSS: 8.8 High, RCE via crafted extension
  • CVE-2026-5877: Use after free in Navigation: 8.8 High, arbitrary code execution in sandbox via crafted web page
  • CVE-2026-5878: Incorrect security UI in Blink: 4.3 Medium, UI spoofing
  • CVE-2026-5879: Insufficient validation of untrusted input in ANGLE: 8.8 High, arbitrary code execution in sandbox via crafted HTML page
  • CVE-2026-5876: Side-channel information leakage in Navigation: 6.5 Medium, cross origin data exfiltration
  • CVE-2026-5880: Incorrect security UI in browser UI: 4.3 Medium, URL bar spoofing
  • CVE-2026-5875: Policy bypass in Blink: 4.3 Medium, UI spoofing
  • CVE-2026-5882: Incorrect security UI in Fullscreen: 4.3 Medium, UI spoofing
  • CVE-2026-5884: Insufficient validation of untrusted input in Media: 8.8 High, arbitrary code execution in sandbox via crafted HTML page
  • CVE-2026-5885: Insufficient validation of untrusted input in WebML: 6.5 Medium, remote attacker can obtain sensitive information from process memory via a crafted web page
  • CVE-2026-5893: Race in V8: 6.8 Medium, RCE (marked as such due to high attack complexity)
  • CVE-2026-5863: Inappropriate implementation in V8: 8.8 High, RCE
  • CVE-2026-5862: Inappropriate implementation in V8: 8.8 High, RCE
  • CVE-2026-5860: Use after free in WebRTC: 8.8 High, RCE
  • CVE-2026-5861: Use after free in V8: 8.8 High, RCE
  • CVE-2026-5865: Type Confusion in V8: 8.8 High, RCE
  • CVE-2026-5866: Use after free in Media: 8.8 High, RCE
  • CVE-2026-5868: Heap buffer overflow in ANGLE: 8.8 High, RCE
  • CVE-2026-5870: Integer overflow in Skia: 8.8 High, RCE
  • CVE-2026-5871: Type Confusion in V8: 8.8 High, RCE
  • CVE-2026-5872: Use after free in Blink: 8.8 High, RCE
  • CVE-2026-5911: Policy bypass in ServiceWorkers: 4.3 Medium, content security policy bypass
  • CVE-2026-6299: Use after free in Prerender: 8.8 High, RCE
  • CVE-2026-5883: Use after free in Media: 8.8 High, RCE
  • CVE-2026-5913: Out of bounds read in Blink: 8.1 High, RCE
  • CVE-2026-5894: Inappropriate implementation in PDF: 4.3 Medium, navigation restriction bypass via malicious PDF
  • CVE-2026-6363: Type Confusion in V8: 8.8 High, RCE
  • CVE-2026-6364: Out of bounds read in Skia: 6.5 Medium, sensitive process memory disclosure via a crafted file
  • CVE-2026-6359: Use after free in Video: 8.8 High, RCE
  • CVE-2026-6300: Use after free in CSS: 8.8 High, RCE
  • CVE-2026-6301: Type Confusion in Turbofan: 8.8 High, RCE
  • CVE-2026-6302: Use after free in Video: 8.8 High, RCE
  • CVE-2026-6303: Use after free in Codecs: 8.8 High, RCE
  • CVE-2026-6304: Use after free in Graphite: 8.3 High, sandbox escape
  • CVE-2026-6305: Heap buffer overflow in PDFium: 8.8 High, RCE via crafted PDF
  • CVE-2026-6306: Heap buffer overflow in PDFium: 8.8 High, RCE via crafted PDF
  • CVE-2026-6308: Out of bounds read in Media: 7.5 High, RCE via crafted UI gestures
  • CVE-2026-6307: Type Confusion in Turbofan: 8.8 High, RCE
  • CVE-2026-6309: Use after free in Viz: 8.3 High, sandbox escape
  • CVE-2026-6360: Use after free in FileSystem: 8.8 High, RCE due to object corruption
  • CVE-2026-6311: Uninitialized Use in Accessibility: 8.3 High, sandbox escape
  • CVE-2026-6312: Insufficient policy enforcement in Passwords: 3.1 Low, cross origin data exfiltration
  • CVE-2026-6313: Insufficient policy enforcement in CORS: 3.1 Low, cross origin data exfiltration
  • CVE-2026-6314: Out of bounds write in GPU: 8.3 High, sandbox escape
  • CVE-2026-6316: Use after free in Forms: 8.8 High, RCE
  • CVE-2026-6361: Heap buffer overflow in PDFium: 8.3 High, RCE via crafted input gestures in a PDF file
  • CVE-2026-6362: Use after free in Codecs: 6.3 Medium, DoS/Information Disclosure/possible RCE via crafted video file
  • CVE-2026-5886: Out of bounds read in WebAudio: 5.3 Medium, sensitive process memory disclosure via crafted HTML
  • CVE-2026-5891: Insufficient policy enforcement in browser UI: 4.3 Medium, UI Spoofing
  • CVE-2026-5873: Out of bounds read and write in V8: 8.8 High, RCE
  • CVE-2026-6298: Heap buffer overflow in Skia: 4.3 Medium, sensitive process memory disclosure via crafted HTML
  • CVE-2026-6297: Use after free in Proxy: 8.3 High, remote attacker in a privileged network position causes sandbox escape
  • CVE-2026-6296: Heap buffer overflow in ANGLE: 9.6 Critical, sandbox escape
  • CVE-2026-6919: Use after free in DevTools: 9.6 Critical, sandbox escape
  • CVE-2026-5901: Policy bypass in DevTools: 6.5 Medium, enterprise host restriction bypass via crafted Chrome extension
  • CVE-2026-6920: Out of bounds read in GPU: 9.6 Critical, sandbox escape
  • CVE-2026-7350: Use after free in WebMIDI: 8.3 High, sandbox escape
  • CVE-2026-7343: Use after free in Views: 7.5 High, sandbox escape
  • CVE-2026-7359: Use after free in ANGLE: 8.8 High, sandbox escape
  • CVE-2026-7340: Integer overflow in ANGLE: 4.3 Medium, information disclosure
  • CVE-2026-7339: Heap buffer overflow in WebRTC: 8.8 High, RCE
  • CVE-2026-7360: Insufficient validation of untrusted input in Compositing: 3.1 Low, site isolation bypass
  • CVE-2026-7335: Use after free in Media: 8.8 High, RCE
  • CVE-2026-7355: Use after free in Media: 8.8 High, RCE
  • CVE-2026-7333: Use after free in GPU: 9.6 Critical, sandbox escape
  • CVE-2026-7357: Use after free in GPU: 7.5 High, RCE
  • CVE-2026-7336: Use after free in WebRTC: 8.8 High, RCE
  • CVE-2026-7356: Use after free in Navigation: 8.8 High, RCE
  • CVE-2026-7354: Out of bounds read and write in Angle: 8.8 High, sandbox escape
  • CVE-2026-7353: Heap buffer overflow in Skia: 8.3 High, sandbox escape
  • CVE-2026-7341: Use after free in WebRTC: 8.8 High, RCE
  • CVE-2026-7342: Use after free in WebView: 8.8 High, RCE
  • CVE-2026-7351: Race in MHTML: 3.1 Low, cross origin data exfiltration
  • CVE-2026-7348: Use after free in Codecs: 8.8 High, RCE
  • CVE-2026-7346: Inappropriate implementation in Tint: 8.1 High, RCE
  • CVE-2026-7345: Insufficient validation of untrusted input in Feedback: 8.3 High, sandbox escape
  • CVE-2026-7349: Use after free in Cast: 7.5 High, RCE via malicious local network traffic
  • CVE-2026-7344: Use after free in Accessibility: 8.8 High, sandbox escape
  • CVE-2026-7363: Use after free in Canvas: 8.8 High, RCE
  • CVE-2026-7917: Use after free in Fullscreen: 8.3 High, sandbox escape
  • CVE-2026-7914: Type Confusion in Accessibility: 8.3 High, sandbox escape
  • CVE-2026-7912: Integer overflow in GPU: 4.2 Medium, remote arbitrary file read/write
  • CVE-2026-7910: Use after free in Views: 9.6 Critical, site isolation bypass
  • CVE-2026-7908: Use after free in Fullscreen: 9.6 Critical, sandbox escape
  • CVE-2026-7907: Use after free in DOM: 8.8 High, RCE
  • CVE-2026-7906: Use after free in SVG: 8.8 High, RCE
  • CVE-2026-7904: Out of bounds read in Fonts: 4.3 Medium, information disclosure
  • CVE-2026-7903: Integer overflow in ANGLE: 8.8 High, RCE
  • CVE-2026-7902: Out of bounds memory access in V8: 8.8 High, RCE
  • CVE-2026-7901: Use after free in ANGLE: 8.8 High, RCE
  • CVE-2026-7900: Heap buffer overflow in ANGLE: 8.3 High, sandbox escape
  • CVE-2026-7899: Out of bounds read and write in V8: 8.8 High, RCE

The total tally for QtWebEngine 6.11.1 is 153 security vulnerabilities fixed. Out of these:

  • 8 Critical
  • 109 High
  • 32 Medium
  • 4 Low

A total of 84 Remote Code Execution vulnerabilities, 23 Sandbox Escapes, and a variety of other impacts including attacker controlled arbitrary file read/writes.

comment:4 by Bruce Dubbs, 4 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:5 by Bruce Dubbs, 4 months ago

Owner: changed from Bruce Dubbs to SecurityAdvisory
Status: assigned → new

Fixed at commits 64869dc7c1 (qtwebengine) and 1f43801bf1 (qt6). Leaving open for sa.

comment:6 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-096 issued for Qt6

SA-13.0-097 issued for QtWebEngine

Note: See TracTickets for help on using tickets.