Predictable Seed in Pseudo-Random Number Generator (PRNG) in Qt - CVE-2024-36048

 

Predictable Seed in Pseudo-Random Number Generator (PRNG) in Qt - CVE-2024-36048

Published: May 28, 2024


Vulnerability identifier: #VU89843
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-36048
CWE-ID: CWE-337
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to QAbstractOAuth in Qt Network Authorization uses only time to seed the PRNG. A remote attacker can guess authorization tokens and bypass authentication.


Affected software

Qt
openEuler
Fedora
qadwaitadecorations
zeal
qgnomeplatform
qt5ct
fcitx-qt5
kddockwidgets
keepassxc
gammaray
fcitx5-qt
deepin-qt5integration
deepin-qt5platform-plugins
qt5-qtnetworkauth-debuginfo
qt5-qtnetworkauth
qt5-qtnetworkauth-debugsource
qt5-qtnetworkauth-devel
qt5-qtnetworkauth-examples
python-qt5
qt5-qtcharts
qt5-qtspeech
qt5-qtserialbus
qt5-qtsensors
qt5-qtscxml
qt5-qtscript
qt5-qtremoteobjects
qt5-qtquickcontrols2
qt5-qtquickcontrols
qt5
qt5-qt3d
qt5-qtbase
qt5-qtserialport
qt5-qtconnectivity
qt5-qtdatavis3d
qt5-qtdeclarative
qt5-qtdoc
qt5-qtgamepad
qt5-qtgraphicaleffects
qt5-qtimageformats
qt5-qtlocation
qt5-qtmultimedia
qt5-qtxmlpatterns
qt5-qtsvg
qt5-qttools
qt5-qttranslations
qt5-qtvirtualkeyboard
qt5-qtx11extras
qt5-qtwebview
qt5-qtwebsockets
qt5-qtwayland
qt5-qtwebchannel
qt5-qtwebengine
dwayland
kf5-kwayland
kf5-frameworkintegration
qt5-qtwebkit
plasma-integration
qt6-qtnetworkauth-devel
qt6-qtnetworkauth-debugsource
qt6-qtnetworkauth-debuginfo
qt6-qtnetworkauth
qt6-qtnetworkauth-examples
python-pyqt6
qt6-qtsvg
qt6-qtgraphs
qt6-qtgrpc
qt6-qtdatavis3d
qt6-qtconnectivity
qt6-qtcoap
qt6-qtcharts
qt6-qt5compat
qt6-qt3d
qt6
qt6-qtspeech
qt6-qtserialport
qt6-qtserialbus
qt6-qtsensors
qt6-qtscxml
qt6-qtremoteobjects
qt6-qtquicktimeline
qt6-qtquick3dphysics
qt6-qtquick3d
qt6-qtopcua
qt6-qthttpserver
qt6-qtimageformats
qt6-qtlocation
qt6-qtlottie
qt6-qtmqtt
qt6-qtmultimedia
qt6-qttools
qt6-qtpositioning
qt6-qtwebview
qt6-qtwebsockets
qt6-qtwebengine
qt6-qtwebchannel
qt6-qtwayland
qt6-qtvirtualkeyboard
qt6-qttranslations
qt6-qtbase
qt6-qtshadertools
qt6-qtlanguageserver
qt6-qtdeclarative
kf5-akonadi-server

How to mitigate CVE-2024-36048

Install updates from vendor's website.

Qt - addressed in versions 5.15.17, 6.7.1
qadwaitadecorations - addressed in versions 0.1.5-3.fc40, 0.1.5-4.fc40
zeal - update to 0.7.0-10.fc40
qgnomeplatform - addressed in versions 0.9.2-14.fc40, 0.9.2-15.fc40
qt5ct - update to 1.1-24.fc40
fcitx-qt5 - update to 1.2.6-21.fc40
kddockwidgets - update to 1.7.0-10.fc40
keepassxc - update to 2.7.8-2.fc40
gammaray - update to 3.0.0-6.fc40
fcitx5-qt - addressed in versions 5.1.6-2.fc40, 5.1.6-3.fc40
deepin-qt5integration - update to 5.6.11-7.fc40
deepin-qt5platform-plugins - update to 5.6.12-7.fc40
qt5-qtnetworkauth-debuginfo - update to 5.15.10-2
qt5-qtnetworkauth - update to 5.15.10-2
qt5-qtnetworkauth-debugsource - update to 5.15.10-2
qt5-qtnetworkauth-devel - update to 5.15.10-2
qt5-qtnetworkauth-examples - update to 5.15.10-2
python-qt5 - update to 5.15.10-6.fc40
qt5-qtnetworkauth - addressed in versions 5.15.13-2.fc39, 5.15.13-2.fc40, 5.15.14-1.fc40
qt5-qtcharts - update to 5.15.14-1.fc40
qt5-qtspeech - update to 5.15.14-1.fc40
qt5-qtserialbus - update to 5.15.14-1.fc40
qt5-qtsensors - update to 5.15.14-1.fc40
qt5-qtscxml - update to 5.15.14-1.fc40
qt5-qtscript - update to 5.15.14-1.fc40
qt5-qtremoteobjects - update to 5.15.14-1.fc40
qt5-qtquickcontrols2 - update to 5.15.14-1.fc40
qt5-qtquickcontrols - update to 5.15.14-1.fc40
qt5 - update to 5.15.14-1.fc40
qt5-qt3d - update to 5.15.14-1.fc40
qt5-qtbase - update to 5.15.14-1.fc40
qt5-qtserialport - update to 5.15.14-1.fc40
qt5-qtconnectivity - update to 5.15.14-1.fc40
qt5-qtdatavis3d - update to 5.15.14-1.fc40
qt5-qtdeclarative - update to 5.15.14-1.fc40
qt5-qtdoc - update to 5.15.14-1.fc40
qt5-qtgamepad - update to 5.15.14-1.fc40
qt5-qtgraphicaleffects - update to 5.15.14-1.fc40
qt5-qtimageformats - update to 5.15.14-1.fc40
qt5-qtlocation - update to 5.15.14-1.fc40
qt5-qtmultimedia - update to 5.15.14-1.fc40
qt5-qtxmlpatterns - update to 5.15.14-1.fc40
qt5-qtsvg - update to 5.15.14-1.fc40
qt5-qttools - update to 5.15.14-1.fc40
qt5-qttranslations - update to 5.15.14-1.fc40
qt5-qtvirtualkeyboard - update to 5.15.14-1.fc40
qt5-qtx11extras - update to 5.15.14-1.fc40
qt5-qtwebview - update to 5.15.14-1.fc40
qt5-qtwebsockets - update to 5.15.14-1.fc40
qt5-qtwayland - update to 5.15.14-1.fc40
qt5-qtwebchannel - update to 5.15.14-1.fc40
qt5-qtwebengine - update to 5.15.16-6.fc40
dwayland - update to 5.25.0-6.fc40
kf5-kwayland - update to 5.115.0-3.fc40
kf5-frameworkintegration - update to 5.115.0-3.fc40
qt5-qtwebkit - update to 5.212.0-0.87alpha4.fc40
plasma-integration - update to 6.0.5-2.fc40
qt6-qtnetworkauth-devel - update to 6.5.2-2
qt6-qtnetworkauth-debugsource - update to 6.5.2-2
qt6-qtnetworkauth-debuginfo - update to 6.5.2-2
qt6-qtnetworkauth - update to 6.5.2-2
qt6-qtnetworkauth-examples - update to 6.5.2-2
python-pyqt6 - update to 6.7.0-2.fc40
qt6-qtsvg - update to 6.7.1-1.fc40
qt6-qtgraphs - update to 6.7.1-1.fc40
qt6-qtgrpc - update to 6.7.1-1.fc40
qt6-qtdatavis3d - update to 6.7.1-1.fc40
qt6-qtconnectivity - update to 6.7.1-1.fc40
qt6-qtcoap - update to 6.7.1-1.fc40
qt6-qtcharts - update to 6.7.1-1.fc40
qt6-qt5compat - update to 6.7.1-1.fc40
qt6-qt3d - update to 6.7.1-1.fc40
qt6 - update to 6.7.1-1.fc40
qt6-qtspeech - update to 6.7.1-1.fc40
qt6-qtserialport - update to 6.7.1-1.fc40
qt6-qtserialbus - update to 6.7.1-1.fc40
qt6-qtsensors - update to 6.7.1-1.fc40
qt6-qtscxml - update to 6.7.1-1.fc40
qt6-qtremoteobjects - update to 6.7.1-1.fc40
qt6-qtquicktimeline - update to 6.7.1-1.fc40
qt6-qtquick3dphysics - update to 6.7.1-1.fc40
qt6-qtquick3d - update to 6.7.1-1.fc40
qt6-qtopcua - update to 6.7.1-1.fc40
qt6-qthttpserver - update to 6.7.1-1.fc40
qt6-qtimageformats - update to 6.7.1-1.fc40
qt6-qtlocation - update to 6.7.1-1.fc40
qt6-qtlottie - update to 6.7.1-1.fc40
qt6-qtmqtt - update to 6.7.1-1.fc40
qt6-qtmultimedia - update to 6.7.1-1.fc40
qt6-qtnetworkauth - update to 6.7.1-1.fc40
qt6-qttools - update to 6.7.1-1.fc40
qt6-qtpositioning - update to 6.7.1-1.fc40
qt6-qtwebview - update to 6.7.1-1.fc40
qt6-qtwebsockets - update to 6.7.1-1.fc40
qt6-qtwebengine - update to 6.7.1-1.fc40
qt6-qtwebchannel - update to 6.7.1-1.fc40
qt6-qtwayland - update to 6.7.1-1.fc40
qt6-qtvirtualkeyboard - update to 6.7.1-1.fc40
qt6-qttranslations - update to 6.7.1-1.fc40
qt6-qtbase - update to 6.7.1-2.fc40
qt6-qtshadertools - update to 6.7.1-2.fc40
qt6-qtlanguageserver - update to 6.7.1-2.fc40
qt6-qtdeclarative - update to 6.7.1-2.fc40
kf5-akonadi-server - update to 23.08.5-3.fc40

External References

Related Security Bulletins