Out-of-bounds write in Qt - CVE-2021-38593
Published: August 30, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when rendering SVG file within in QOutlineMapper::convertPath. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger out-of-bounds write and crash the application.
Affected software
Gentoo Linux
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Ubuntu
openEuler
Fedora
Telemetry Dashboard
Liquidware
Citrix Workspace App
Business Automation Insights
Webex App VDI
Pair
Dell Peripheral Manager
IBM Cloud Pak for Security
IBM Cloud Pak for Business Automation
QRadar Suite
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
Red Hat OpenShift Container Platform
libqt5core5a (Ubuntu package)
libqt5gui5 (Ubuntu package)
qt5-qtbase-devel
qt5-qtbase-postgresql
qt5-qtbase-odbc
qt5-qtbase-debuginfo
qt5-qtbase-debugsource
qt5-qtbase-mysql
qt5-qtbase-common
qt5-qtbase
qt5-qtbase-gui
qt5-qtbase-private-devel
qt5-qtbase-examples
qt5-qtbase-static
qt5-qtbase (Red Hat package)
dev-qt/qtgui
How to mitigate CVE-2021-38593
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF004, 25.0.0
Business Automation Insights - update to 24.0.1.0.4
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Pair - update to 1.2.3
Dell Peripheral Manager - update to 1.7.3
Red Hat OpenShift Container Platform - update to 4.11.0
libqt5core5a (Ubuntu package) - update to 5.9.5+dfsg-0ubuntu2.6
libqt5gui5 (Ubuntu package) - update to 5.9.5+dfsg-0ubuntu2.6
qt5-qtbase-devel - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase-postgresql - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase-odbc - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase-debuginfo - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase-debugsource - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase-mysql - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase-common - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase-gui - addressed in versions 5.11.1-13, 5.15.2-3
qt5-qtbase-private-devel - update to 5.15.2-3
qt5-qtbase-examples - update to 5.15.2-3
qt5-qtbase-static - update to 5.15.2-3
qt5-qtbase (Red Hat package) - update to 5.15.2-4.el8
qt5-qtbase-common - update to 5.15.2-4.0.1
qt5-qtbase-private-devel - update to 5.15.2-4.0.1
qt5-qtbase-postgresql - update to 5.15.2-4.0.1
qt5-qtbase - update to 5.15.2-4.0.1
qt5-qtbase-devel - update to 5.15.2-4.0.1
qt5-qtbase-examples - update to 5.15.2-4.0.1
qt5-qtbase-gui - update to 5.15.2-4.0.1
qt5-qtbase-mysql - update to 5.15.2-4.0.1
qt5-qtbase-odbc - update to 5.15.2-4.0.1
qt5-qtbase - addressed in versions 5.15.2-31.fc35, 5.15.3-2.fc36
dev-qt/qtgui - update to 5.15.9-r1
External References
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/qt/OSV-2021-903.yaml
- https://github.com/qt/qtbase/commit/6b400e3147dcfd8cc3a393ace1bd118c93762e0c
- https://github.com/qt/qtbase/commit/1ca02cf2879a5e1511a2f2109f0925cf4c892862
- https://github.com/qt/qtbase/commit/202143ba41f6ac574f1858214ed8bf4a38b73ccd
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=35566
- https://www.qt.io/blog/qt-5.15-extended-support-for-subscription-license-holders
- https://wiki.qt.io/Qt_5.15_Release#Known_Issues
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36VN2WKMNQUSTF6ZW2X52NPAJVXJ4S5I/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HY5YCSDCTLHVMP3OXOM6HNTWHV6DBHDX/
Related Security Bulletins
- Denial of service in Qt
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Red Hat Enterprise Linux 8 update for qt5-qtbase
- Ubuntu update for qtbase-opensource-src
- Gentoo update for QtGui
- openEuler 20.03 LTS SP3 update for qt5-qtbase
- openEuler 22.03 LTS update for qt5-qtbase
- Multiple vulnerabilities in Dell Peripheral Manager
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Dell Pair
- Fedora 35 update for qt5-qtbase
- Fedora 36 update for qt5-qtbase
- Anolis OS update for qt5-qtbase
- Multiple vulnerabilities in IBM Cloud Pak for Security and IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Business Automation Insights