Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Red Hat Enterprise Linux 8 RHSA-2021-4172 Moderate: Qt5 Out Of Bounds Read

red hat
Calendar Grey November 9, 2021
Dist Redhat Esm H88
A notification has been issued regarding an update for qt5 within Red Hat Enterprise Linux 8, aimed at resolving a moderate security vulnerability alongside essential bug corrections.
An update for qt5 is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Qt is a software toolkit for developing applications.
The following packages have been upgraded to a later upstream version: adwaita-qt (1.2.1), python-qt5 (5.15.0), qgnomeplatform (0.7.1), qt5 (5.15.2), qt5-qt3d (5.15.2), qt5-qtbase (5.15.2), qt5-qtconnectivity (5.15.2), qt5-qtdeclarative (5.15.2), qt5-qtdoc (5.15.2), qt5-qtgraphicaleffects (5.15.2), qt5-qtimageformats (5.15.2), qt5-qtlocation (5.15.2), qt5-qtmultimedia (5.15.2), qt5-qtquickcontrols (5.15.2), qt5-qtquickcontrols2 (5.15.2), qt5-qtscript (5.15.2), qt5-qtsensors (5.15.2), qt5-qtserialbus (5.15.2), qt5-qtserialport (5.15.2), qt5-qtsvg (5.15.2), qt5-qttools (5.15.2), qt5-qttranslations (5.15.2), qt5-qtwayland (5.15.2), qt5-qtwebchannel (5.15.2), qt5-qtwebsockets (5.15.2), qt5-qtx11extras (5.15.2), qt5-qtxmlpatterns (5.15.2), sip (4.19.24). (BZ#1928156)
Security Fix(es):
* qt: Out of bounds read in function QRadialFetchSimd from crafted svg file (CVE-2021-3481)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2021-3481 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.5_release_notes/index

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: adwaita-qt-1.2.1-3.el8.src.rpm python-qt5-5.15.0-2.el8.src.rpm qgnomeplatform-0.7.1-2.el8.src.rpm qt5-5.15.2-1.el8.src.rpm qt5-qt3d-5.15.2-2.el8.src.rpm qt5-qtbase-5.15.2-3.el8.src.rpm qt5-qtcanvas3d-5.12.5-3.el8.src.rpm qt5-qtconnectivity-5.15.2-2.el8.src.rpm qt5-qtdeclarative-5.15.2-2.el8.src.rpm qt5-qtdoc-5.15.2-1.el8.src.rpm qt5-qtgraphicaleffects-5.15.2-2.el8.src.rpm qt5-qtimageformats-5.15.2-2.el8.src.rpm qt5-qtlocation-5.15.2-2.el8.src.rpm qt5-qtmultimedia-5.15.2-2.el8.src.rpm qt5-qtquickcontrols-5.15.2-2.el8.src.rpm qt5-qtquickcontrols2-5.15.2-2.el8.src.rpm qt5-qtscript-5.15.2-2.el8.src.rpm qt5-qtsensors-5.15.2-2.el8.src.rpm qt5-qtserialbus-5.15.2-3.el8.src.rpm qt5-qtserialport-5.15.2-2.el8.src.rpm qt5-qtsvg-5.15.2-3.el8.src.rpm qt5-qttools-5.15.2-3.el8.src.rpm qt5-qttranslations-5.15.2-1.el8.src.rpm qt5-qtwayland-5.15.2-2.el8.src.rpm qt5-qtwebchannel-5.15.2-2.el8.src.rpm qt5-qtwebsockets-5.15.2-2.el8.src.rpm qt5-qtx11extras-5.15.2-2.el8.src.rpm qt5-qtxmlpatterns-5.15.2-2.el8.src.rpm sip-4.19.24-2.el8.src.rpm
aarch64: adwaita-qt-debuginfo-1.2.1-3.el8.aarch64.rpm adwaita-qt-debugsource-1.2.1-3.el8.aarch64.rpm adwaita-qt5-1.2.1-3.el8.aarch64.rpm adwaita-qt5-debuginfo-1.2.1-3.el8.aarch64.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2021:4172-01
Product: Red Hat Enterprise Linux
Issue date: 2021-11-09

Topic

An update for qt5 is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64

Red Hat Enterprise Linux CRB (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64

Bugs Fixed

1928156 - [Rebase] Rebase Qt5 to Qt 5.15

1930039 - Rebase qt5-doc to Qt 5.15.2

1930040 - Rebase qt5-qtbase to Qt 5.15.2

1930041 - Rebase qt5-qtcanvas3d to Qt 5.15.2

1930042 - Rebase qt5-qtconnectivity to Qt 5.15.2

1930043 - Rebase qt5-qtdeclarative to Qt 5.15.2

1930044 - Rebase qt5-qtdoc to Qt 5.15.2

1930045 - Rebase qt5-qtgraphicaleffects to Qt 5.15.2

1930046 - Rebase qt5-qtimageformats to Qt 5.15.2

1930047 - Rebase qt5-qtlocation to Qt 5.15.2

1930048 - Rebase qt5-qtmultimedia to Qt 5.15.2

1930049 - Rebase qt5-qtquickcontrols to Qt 5.15.2

1930050 - Rebase qt5-qtquickcontrols2 to Qt 5.15.2

1930051 - Rebase qt5-qtscript to Qt 5.15.2

1930052 - Rebase qt5-qtsensors to Qt 5.15.2

1930053 - Rebase qt5-qtserialbus to Qt 5.15.2

1930054 - Rebase qt5-qtserialport to Qt 5.15.2

1930055 - Rebase qt5-qtsvg to Qt 5.15.2

1930056 - Rebase qt5-qttools to Qt 5.15.2

1930057 - Rebase qt5-qttranslations to Qt 5.15.2

1930058 - Rebase qt5-qtwayland to Qt 5.15.2

1930059 - Rebase qt5-qtwebchannel to Qt 5.15.2

1930060 - Rebase qt5-qtwebsockets to Qt 5.15.2

1930061 - Rebase qt5-qtxmlpatterns to Qt 5.15.2

1930062 - Rebase qt5-qtx11extras to Qt 5.15.2

1930063 - Rebase qt5-qt3d to Qt 5.15.2

1930073 - Rebase QGnomePlatform to 0.7.0

1930074 - Rebase Adwaita-qt to 1.3.0

1931444 - CVE-2021-3481 qt: Out of bounds read in function QRadialFetchSimd from crafted svg file

1949066 - Rebase python-qt5 to support Qt 5.15

1949080 - Rebase sip to 4.19.23

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here