Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 40: 2024-bfb8617ba3 Moderate: Qt6 Guessable Values Exploit

fedora
Calendar Grey May 29, 2024
Dist Fedora Esm H88
Keep updated with the recent Fedora 40 announcement regarding the qt6-qtscxml patch that resolves a significant PRNG vulnerability along with additional improvements.
Qt 6.7.1 bugfix update.

Summary

The Qt SCXML module provides functionality to create state machines from SCXML files.

This includes both dynamically creating state machines loading the SCXML file and instantiating states and transitions)

and generating a C++ file that has a class implementing the state machine.

It also contains functionality to support data models and executable content.

Update Information:

Qt 6.7.1 bugfix update.

Change Log

* Tue May 21 2024 Jan Grulich - 6.7.1-1 - 6.7.1

References


[ 1 ] Bug #2282868 - CVE-2024-36048 qt6-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2282868 [ 2 ] Bug #2282870 - CVE-2024-36048 qt6-qtnetworkauth: qtnetworkauth: badly seeded PRNG may result in guessable values [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2282870

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-bfb8617ba3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: qt6-qtscxml
Product: Fedora 40
Version: 6.7.1
Release: 1.fc40
Summary: Qt6 - ScXml component

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here