[qt/qt/qtwebengine]: Summary of bulk changes made
KDE Git Services - Bulk Change <[email protected]>
| Newsgroups | gmane.comp.kde.cvs |
|---|---|
| Message-ID | <[email protected]> |
Git repository change summary for qt/qt/qtwebengine Pushed by mirror-service into branch '6.12'. Changed from 504df56e45af658f5a8038c1af61346d753f50a3 to f07dde736c9c5c9a110e8714dbdc38696381d442 Acknowledgement was received that this change introduces only existing code that has been pushed to another public open source repository. This change contains the following new commits: Git commit c9b5c6a93c738a629f3ed152083bbe8c378d3944 by Qt Cherry-pick Bot (on behalf of Michal Klocek) on 30/07/2026 at 13:49.. Update Chromium Submodule src/3rdparty 1e2ffa9c..2b58222c: * [Backport] CVE-2026-16804: Use after free in Input * [Backport] Security bug 459347936 / Dependency for CVE-2026-16804 * [Backport] CVE-2026-16805: Use after free in Blink * [Backport] CVE-2026-16807: Out of bounds write in Codecs * [Backport] CVE-2026-15107: Use after free in IndexedDB * [Backport] Dependency for CVE-2026-15107 * [Backport] CVE-2026-13910: Insufficient policy enforcement in WebXR * [backport] CVE-2026-13992: Inappropriate implementation in UI * [backport] CVE-2026-13988: Inappropriate implementation in Paint * [backport] Dependency for CVE-2026-13988 * [backport] CVE-2026-13979: Inappropriate implementation in Paint (5/5) * [backport] CVE-2026-13979: Inappropriate implementation in Paint (4/5) * [backport] CVE-2026-13979: Inappropriate implementation in Paint (3/5) * [backport] CVE-2026-13979: Inappropriate implementation in Paint (2/5) * [backport] CVE-2026-13979: Inappropriate implementation in Paint (1/5) * [backport] CVE-2026-13977: Inappropriate implementation in HTMLParser * [backport] CVE-2026-13975: Out of bounds read in ANGLE * [backport] CVE-2026-13972: Inappropriate implementation in Paint * [backport] CVE-2026-13971: Uninitialized Use in Skia * [backport] CVE-2026-13970: Uninitialized Use in Media * [backport] CVE-2026-13969: Uninitialized Use in UI * [backport] CVE-2026-13966: Inappropriate implementation in History * [backport] CVE-2026-13965: Use after free in Oilpan * [backport] CVE-2026-13961: Insufficient validation of untrusted input in DevTools * [backport] CVE-2026-13959: Insufficient validation of untrusted input in Blink * [backport] CVE-2026-13958: Uninitialized Use in Codecs * [rust][harfbuzz][qt3rdparty] Build harfbuzz without rust * [roll][harfbuz] CVE-2026-13938: Integer overflow in Fonts * [roll][libvpx] CVE-2026-13906: Out of bounds read in Codecs Pick-to: 6.11 Change-Id: If855211f468238b1178c4fbc4b0c882c8a2f2b50 Reviewed-by: Moss Heim <[email protected]> (cherry picked from commit 7f476f59cf5d00a3b47b52331b37f99d52b616b7) Reviewed-by: Qt Cherry-pick Bot <[email protected]> https://invent.kde.org/qt/qt/qtwebengine/-/commit/c9b5c6a93c738a629f3ed152083bbe8c378d3944 Git commit 9eca610ba6dbc2cdcc872526150b15cf6eba1a1b by Qt Cherry-pick Bot (on behalf of Allan Sandfeld Jensen) on 30/07/2026 at 13:49.. Document apparmor restrictions on QtWebEngine sandboxing Otherwise we end up unsandboxed on Ubuntu based distros. Task-number: QTBUG-148479 Change-Id: Ib606b5b4513984ea741897e6887ae93ae9fba9d1 Reviewed-by: Moss Heim <[email protected]> (cherry picked from commit aced057f09bf6c709881d275179530e639dd7050) Reviewed-by: Qt Cherry-pick Bot <[email protected]> https://invent.kde.org/qt/qt/qtwebengine/-/commit/9eca610ba6dbc2cdcc872526150b15cf6eba1a1b Git commit f07dde736c9c5c9a110e8714dbdc38696381d442 by Qt Cherry-pick Bot (on behalf of Michal Klocek) on 30/07/2026 at 13:49.. Update Chromium Submodule src/3rdparty 2b58222c..ba7ac37c: * [fixup][rust][harfbuzz] Build harfbuzz without rust * [fixup] [Backport] CVE-2026-14421: Uninitialized Use in Dawn * [Backport] CVE-2026-14032: Use after free in Bluetooth * [Backport] CVE-2026-14025: Use after free in Views * [Backport] CVE-2026-16424: Use after free in GPU * [Backport] CVE-2026-16423: Use after free in UI * [Backport] CVE-2026-16422: Insufficient validation of untrusted input in Certificate * [Backport] CVE-2026-16419: Out of bounds read and write in ANGLE * [Backport] CVE-2026-16418: Stack buffer overflow in V8 * [Backport] CVE-2026-16417: Uninitialized Use in Skia * [Backport] CVE-2026-16413: Out of bounds write in ANGLE * [Backport] CVE-2026-16420/CVE-2026-16421: Type Confusion in WebAudio/Inappropriate Implementation in WebAudio * Look for system installed sandbox launcher * [Backport] CVE-2026-15133: Use after free in InterestGroups * [Backport] CVE-2026-11673: Use after free in InterestGroups * [Backport] CVE-2026-14421: Uninitialized Use in Dawn * [Backport] CVE-2026-14408: Uninitialized Use in Dawn * [Backport] CVE-2026-11266: Policy bypass in SafeBrowsing * [fixup][3rdparty] Unbundle Linux system libraries for GN Pick-to: 6.11 Change-Id: Ic4f42b914a6a884ae5205f0c2728b69bf05a57b4 Reviewed-by: Moss Heim <[email protected]> (cherry picked from commit fb532afe3c409fe08adc4359cc321e1544ed643d) Reviewed-by: Qt Cherry-pick Bot <[email protected]> https://invent.kde.org/qt/qt/qtwebengine/-/commit/f07dde736c9c5c9a110e8714dbdc38696381d442