Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE 15 SP4: 2022:10049-1 Moderate: libqt5-qtwebengine Memory Access

opensuse
Calendar Grey July 10, 2022
Dist Opensuse Esm H88
Addresses 7 security issues in openSUSE's libqt5-qtwebengine, enhancing stability and efficiency. Update advised.
An update that fixes 7 vulnerabilities is now available

Description

This update for libqt5-qtwebengine fixes the following issues:

Update to version 5.15.10:

* Fix top level build with no widget

* Fix read-after-free on EGL extensions

* Update Chromium

* Add workaround for unstable gn on macOS in ci

* Pass archiver to gn build

* Fix navigation to non-local URLs

* Add support for universal builds for qtwebengine and qtpdf

* Enable Apple Silicon support

* Fix cross compilation x86_64->arm64 on mac

* Bump version to 5.15.10

* CustomDialogs: Make custom input fields readable in dark mode

* CookieBrowser: Make alternating rows readable in dark mode

* Update Chromium:

* Bump V8_PATCH_LEVEL

* Fix clang set-but-unused-variable warning

* Fix mac toolchain python linker script call

* Fix missing dependency for gpu sources

* Fix python calls

* Fix undefined symbol for universal link

* Quick fix for regression in service workers by reverting backports

* [Backport]...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2022-10049=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 x86_64):

libQt5Pdf5-5.15.10-bp154.2.3.2

libQt5PdfWidgets5-5.15.10-bp154.2.3.2

libqt5-qtpdf-devel-5.15.10-bp154.2.3.2

libqt5-qtpdf-examples-5.15.10-bp154.2.3.2

libqt5-qtpdf-imports-5.15.10-bp154.2.3.2

libqt5-qtwebengine-5.15.10-bp154.2.3.2

libqt5-qtwebengine-devel-5.15.10-bp154.2.3.2

libqt5-qtwebengine-examples-5.15.10-bp154.2.3.2

- openSUSE Backports SLE-15-SP4 (noarch):

libqt5-qtpdf-private-headers-devel-5.15.10-bp154.2.3.2

libqt5-qtwebengine-private-headers-devel-5.15.10-bp154.2.3.2

References

https://www.suse.com/security/cve/CVE-2022-0797.html

https://www.suse.com/security/cve/CVE-2022-1125.html

https://www.suse.com/security/cve/CVE-2022-1138.html

https://www.suse.com/security/cve/CVE-2022-1305.html

https://www.suse.com/security/cve/CVE-2022-1310.html

https://www.suse.com/security/cve/CVE-2022-1314.html

https://www.suse.com/security/cve/CVE-2022-1493.html

Announcement ID: openSUSE-SU-2022:10049-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here