Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 39: 2024-826bf5a09a Critical Pointer Authentication Fix

fedora
Calendar Grey June 22, 2024
Dist Fedora Esm H88
Fedora 39 has released a webkitgtk update addressing a significant vulnerability linked to pointer authentication. Please ensure to install this update without delay.
Update to 2.44.2: Make gamepads visible on axis movements, and not only on button presses

Summary

WebKitGTK is the port of the WebKit web rendering engine to the

GTK platform.

Update Information:

Update to 2.44.2: Make gamepads visible on axis movements, and not only on button presses. Disable the gst-libav AAC decoder. Make user scripts and style sheets visible in the Web Inspector. Use the geolocation portal where available, with the existing geoclue as fallback if the portal is not usable. Use the printing portal when running sandboxed. Use the file transfer portal for drag and drop when running sandboxed. Avoid notifying an empty cursor rectangle to input methods. Remove empty bar shown in detached inspector windows. Consider keycode when activating application accelerators. Fix several crashes and rendering issues. Fix CVE-2024-27834

Change Log

* Sat Jun 8 2024 Michael Catanzaro - 2.44.2-2 - Add patch to fix excessive CPU usage * Thu May 16 2024 Michael Catanzaro - 2.44.2-1 - Update to 2.44.2 * Thu Apr 18 2024 Michael Catanzaro - 2.44.1-2 - Request 4 GB of RAM per vCPU

References


[ 1 ] Bug #2282414 - CVE-2024-27834 webkitgtk: webkit: pointer authentication bypass [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2282414

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-826bf5a09a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: webkitgtk
Product: Fedora 39
Version: 2.44.2
Release: 2.fc39
Summary: GTK web content engine library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here