qtbase-opensource-src.git
2 months agofix buffer overflow in Qt SVG
Debian Qt/KDE Maintainers [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
fix buffer overflow in Qt SVG

Origin: upstream, https://download.qt.io/official_releases/qt/5.15/CVE-2023-32763-qtbase-5.15.diff
Last-Update: 2023-05-22

Adds qAddOverflow and qMulOverflow definitions to QFixed.

Gbp-Pq: Name CVE-2023-32763.diff

2 months agoCVE-2024-25580
Debian Qt/KDE Maintainers [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
CVE-2024-25580

Gbp-Pq: Name CVE-2024-25580.diff

2 months ago[PATCH] Fix invalid pointer return with QGridLayout::itemAt(-1)
Zhang Yu [Mon, 22 Feb 2021 01:25:01 +0000 (09:25 +0800)]
[PATCH] Fix invalid pointer return with QGridLayout::itemAt(-1)

QGridLayout::takeAt() and QLayoutItem *itemAt() only check the upper bound.
If the index < 0, these function will return invalid pointer.

Fixes: QTBUG-91261
Pick-to: 5.15 6.0 6.1
Change-Id: Idfb9fb6228b9707f817353b04974da16205a835c
Reviewed-by: Giuseppe D'Angelo <giuseppe.dangelo@kdab.com>
Gbp-Pq: Name fix-invalid-pointer-return-with-QGridLayout.diff

2 months agoadjust QMimeDatabase implementation
Debian Qt/KDE Maintainers [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
adjust QMimeDatabase implementation

Origin: upstream, https://code.qt.io/cgit/qt/qtbase.git/commit/?id=0cbbba2aa5b47224
Last-Update: 2021-06-12

When multiple globs match, and the result from magic sniffing is
unrelated to any of those globs, globs have priority and one of them
should be picked up.

Gbp-Pq: Name mime_globs.diff

2 months agofix allocated memory of QByteArray returned by QIODevice::readLine
Debian Qt/KDE Maintainers [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
fix allocated memory of QByteArray returned by QIODevice::readLine

Origin: upstream, https://code.qt.io/cgit/qt/qtbase.git/commit/?id=6485b6d45ad165cf
Last-Update: 2021-02-20

Gbp-Pq: Name qiodevice_readline_memory.diff

2 months agoinclude <limits> to fix some GCC 11 build issues
Debian Qt/KDE Maintainers [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
include <limits> to fix some GCC 11 build issues

Origin: upstream, commits:
 https://code.qt.io/cgit/qt/qtbase.git/commit/?id=813a928c7c3cf986
 https://code.qt.io/cgit/qt/qtbase.git/commit/?id=9c56d4da2ff631a8
Last-Update: 2021-01-26

Gbp-Pq: Name gcc_11_limits.diff

2 months agoQNAM: work around QObject finicky orphan cleanup details
Debian Qt/KDE Maintainers [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
QNAM: work around QObject finicky orphan cleanup details

Origin: upstream, https://code.qt.io/cgit/qt/qtbase.git/commit/?id=0807f16eb407eaf8
Last-Update: 2021-01-26

Gbp-Pq: Name qnam_connect_memory_leak.diff

2 months agoAvoid use-after-free in QXcbConnection::initializeScreens()
Debian Qt/KDE Maintainers [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
Avoid use-after-free in QXcbConnection::initializeScreens()

Origin: upstream, https://code.qt.io/cgit/qt/qtbase.git/commit/?id=86b8c5c3f32c2457
Last-Update: 2020-11-23

Gbp-Pq: Name xcb_screens_uaf.patch

2 months agoqtbase-opensource-src (5.15.2+dfsg-9+deb11u2) bullseye-security; urgency=high
Sylvain Beucler [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
qtbase-opensource-src (5.15.2+dfsg-9+deb11u2) bullseye-security; urgency=high

  * Non-maintainer upload by the LTS Security Team.
  * CVE-2024-39936: issue in HTTP2. Code to make security-relevant
    decisions about an established connection may execute too early,
    because the encrypted() signal has not yet been emitted and
    processed.
  * Add Salsa-CI configuration
  * Add git-buildpackage configuration
  * Add lintian overrides for test binary data

[dgit import unpatched qtbase-opensource-src 5.15.2+dfsg-9+deb11u2]

2 months agoImport qtbase-opensource-src_5.15.2+dfsg-9+deb11u2.debian.tar.xz
Sylvain Beucler [Thu, 27 Nov 2025 14:54:31 +0000 (15:54 +0100)]
Import qtbase-opensource-src_5.15.2+dfsg-9+deb11u2.debian.tar.xz

[dgit import tarball qtbase-opensource-src 5.15.2+dfsg-9+deb11u2 qtbase-opensource-src_5.15.2+dfsg-9+deb11u2.debian.tar.xz]

5 years agoImport qtbase-opensource-src_5.15.2+dfsg.orig.tar.xz
Dmitry Shachnev [Fri, 20 Nov 2020 13:08:35 +0000 (16:08 +0300)]
Import qtbase-opensource-src_5.15.2+dfsg.orig.tar.xz

[dgit import orig qtbase-opensource-src_5.15.2+dfsg.orig.tar.xz]