The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-9486 http://linux.oracle.com/errata/ELSA-2025-9486.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: qt6-qtbase-6.8.1-9.el10_0.x86_64.rpm qt6-qtbase-common-6.8.1-9.el10_0.noarch.rpm qt6-qtbase-devel-6.8.1-9.el10_0.x86_64.rpm qt6-qtbase-examples-6.8.1-9.el10_0.x86_64.rpm qt6-qtbase-gui-6.8.1-9.el10_0.x86_64.rpm qt6-qtbase-mysql-6.8.1-9.el10_0.x86_64.rpm qt6-qtbase-odbc-6.8.1-9.el10_0.x86_64.rpm qt6-qtbase-postgresql-6.8.1-9.el10_0.x86_64.rpm qt6-qtbase-private-devel-6.8.1-9.el10_0.x86_64.rpm qt6-qtbase-static-6.8.1-9.el10_0.x86_64.rpm aarch64: qt6-qtbase-6.8.1-9.el10_0.aarch64.rpm qt6-qtbase-common-6.8.1-9.el10_0.noarch.rpm qt6-qtbase-devel-6.8.1-9.el10_0.aarch64.rpm qt6-qtbase-examples-6.8.1-9.el10_0.aarch64.rpm qt6-qtbase-gui-6.8.1-9.el10_0.aarch64.rpm qt6-qtbase-mysql-6.8.1-9.el10_0.aarch64.rpm qt6-qtbase-odbc-6.8.1-9.el10_0.aarch64.rpm qt6-qtbase-postgresql-6.8.1-9.el10_0.aarch64.rpm qt6-qtbase-private-devel-6.8.1-9.el10_0.aarch64.rpm qt6-qtbase-static-6.8.1-9.el10_0.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/qt6-qtbase-6.8.1-9.el10_0.src.rpm Related CVEs: CVE-2025-5455 Description of changes: [6.8.1-9] - qt5: qt6: QtCore Assertion Failure Denial of Service (CVE-2025-5455) _______________________________________________ El-errata mailing list
Several issues have been found in qtbase-opensource-src, a collection of several Qt modules/libraries. The issues are related to buffer overflows, infinite loops or application . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3805-1
In Qt5's plugin loader code as found in qtbase-opensource-src, it was possible to (side-)load plugins from "the" local folder in addition to a system-widely defined library path. . Package : qtbase-opensource-src Version : 5.3.2+dfsg-4+deb8u4 CVE ID : CVE-2020-0569 In Qt5's plugin loader code as found in qtbase-opensource-src, it was possible to (side-)load plugins from "the" local folder in addition to a system-widely defined library path. For Debian 8 "Jessie", this problem has been fixed in version 5.3.2+dfsg-4+deb8u4. We recommend that you upgrade your qtbase-opensource-src packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
An out-of-bounds memory access was discovered in the Qt library, which could result in denial of service through a text file containing many directional characters. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4556-1
Multiple issues were fixed in Qt. CVE-2018-15518 A double-free or corruption during parsing of a specially crafted . Package : qtbase-opensource-src Version : 5.3.2+dfsg-4+deb8u3 CVE ID : CVE-2018-15518 CVE-2018-19870 CVE-2018-19873 Multiple issues were fixed in Qt. CVE-2018-15518 A double-free or corruption during parsing of a specially crafted illegal XML document. CVE-2018-19870 A malformed GIF image might have caused a NULL pointer dereference in QGifHandler resulting in a segmentation fault. CVE-2018-19873 QBmpHandler had a buffer overflow via BMP data. For Debian 8 "Jessie", these problems have been fixed in version 5.3.2+dfsg-4+deb8u3. We recommend that you upgrade your qtbase-opensource-src packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : qtbase-opensource-src Version : 5.3.2+dfsg-4+deb8u3 CVE ID : CVE-2018-15518 CVE-2018-19870. cve-2018-15518, double-free, corruption, during, parsing. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.