There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how QHttp2Stream uploads the body of a POST request and the simultaneous handling of HTTP error responses. This issue only affects Qt 6.9.0 and has been fixed for Qt 6.9.1.
{
"binaries": [
{
"binary_name": "libqt5gui5-gles",
"binary_version": "5.5.1+dfsg-16ubuntu6"
},
{
"binary_name": "libqt5opengl5-gles",
"binary_version": "5.5.1+dfsg-16ubuntu6"
},
{
"binary_name": "libqt5opengl5-gles-dev",
"binary_version": "5.5.1+dfsg-16ubuntu6"
},
{
"binary_name": "qt5-qmake-gles",
"binary_version": "5.5.1+dfsg-16ubuntu6"
},
{
"binary_name": "qtbase5-gles-dev",
"binary_version": "5.5.1+dfsg-16ubuntu6"
},
{
"binary_name": "qtbase5-private-gles-dev",
"binary_version": "5.5.1+dfsg-16ubuntu6"
}
]
}{
"binaries": [
{
"binary_name": "libqt6concurrent6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6core6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6dbus6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6gui6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6network6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6opengl6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6opengl6-dev",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6openglwidgets6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6printsupport6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6sql6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6sql6-ibase",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6sql6-mysql",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6sql6-odbc",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6sql6-psql",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6sql6-sqlite",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6test6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6widgets6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "libqt6xml6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "qmake6",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "qmake6-bin",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "qt6-base-dev",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "qt6-base-dev-tools",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "qt6-base-private-dev",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "qt6-gtk-platformtheme",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "qt6-qpa-plugins",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
},
{
"binary_name": "qt6-xdgdesktopportal-platformtheme",
"binary_version": "6.2.4+dfsg-2ubuntu1.1"
}
]
}{
"binaries": [
{
"binary_name": "libqt6concurrent6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6core6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6dbus6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6gui6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6network6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6opengl6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6openglwidgets6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6printsupport6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6sql6-ibase",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6sql6-mysql",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6sql6-odbc",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6sql6-psql",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6sql6-sqlite",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6sql6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6test6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6widgets6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "libqt6xml6t64",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qmake6",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qmake6-bin",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-base-dev",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-base-dev-tools",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-base-doc-dev",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-base-doc-html",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-base-examples",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-base-private-dev",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-gtk-platformtheme",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-qpa-plugins",
"binary_version": "6.4.2+dfsg-21.1build5"
},
{
"binary_name": "qt6-xdgdesktopportal-platformtheme",
"binary_version": "6.4.2+dfsg-21.1build5"
}
]
}{
"binaries": [
{
"binary_name": "libqt6concurrent6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6core6t64",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6dbus6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6gui6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6network6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6opengl6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6openglwidgets6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6printsupport6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6sql6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6sql6-ibase",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6sql6-mysql",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6sql6-odbc",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6sql6-psql",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6sql6-sqlite",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6test6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6widgets6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "libqt6xml6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qmake6",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qmake6-bin",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-base-dev",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-base-dev-tools",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-base-doc-dev",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-base-doc-html",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-base-examples",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-base-private-dev",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-gtk-platformtheme",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-qpa-plugins",
"binary_version": "6.9.2+dfsg-1ubuntu1"
},
{
"binary_name": "qt6-xdgdesktopportal-platformtheme",
"binary_version": "6.9.2+dfsg-1ubuntu1"
}
]
}