Bug 33159 - qtbase5, qtbase6 new security issues CVE-2023-51714, CVE-2024-25580 and CVE-2024-39936
Summary: qtbase5, qtbase6 new security issues CVE-2023-51714, CVE-2024-25580 and CVE-2...
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-04-30 16:55 CEST by Nicolas Salguero
Modified: 2024-07-12 12:21 CEST (History)
1 user (show)

See Also:
Source RPM: qtbase5, qtbase6
CVE: CVE-2023-51714, CVE-2024-25580, CVE-2024-39936
Status comment:


Attachments

Description Nicolas Salguero 2024-04-30 16:55:50 CEST
RedHat has issued an advisory on April 30:
https://lwn.net/Articles/971686/
Nicolas Salguero 2024-04-30 16:57:16 CEST

CVE: (none) => CVE-2023-51714, CVE-2024-25580
Source RPM: (none) => qtbase5, qtbase6
Whiteboard: (none) => MGA9TOO

Comment 1 Lewis Smith 2024-04-30 20:46:57 CEST
RedHat:
An update for qt5-qtbase is now available
* qt: incorrect integer overflow check (CVE-2023-51714)
* qtbase: potential buffer overflow when reading KTX images (CVE-2024-25580)
For more details about the security issue(s) ... refer to the CVE page(s) listed in the References section.

which I do not see. This must be the case for other RedHat advisories where I complain about no sign of the issued fix.

Note this is for *both* gt5 & qt6.
Assigning globally because different packagers deal with these.

Assignee: bugsquad => pkg-bugs

Comment 2 David GEIGER 2024-06-15 11:40:52 CEST
For Qt6 in Cauldron:

- CVE-2023-51714 was fixes since Qt 6.6.2 that we have
- CVE-2024-25580 was fixes since Qt 6.6.2 that we have

So Qt5 and Qt6 for mga9 should still be fixed and only Qt5 for Caudron should still be fixed!

CC: (none) => geiger.david68210

Comment 3 Nicolas Salguero 2024-07-12 12:20:12 CEST
Fodora has issued an advisory on July 11:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KVCBTKX6LVBTP6UEJQZ2PENI2KATSRJK/

CVE: CVE-2023-51714, CVE-2024-25580 => CVE-2023-51714, CVE-2024-25580, CVE-2024-39936
Summary: qtbase5, qtbase6 new security issues CVE-2023-51714 and CVE-2024-25580 => qtbase5, qtbase6 new security issues CVE-2023-51714, CVE-2024-25580 and CVE-2024-39936


Note You need to log in before you can comment on or make changes to this bug.