Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Red Hat Enterprise Linux 8 RHSA-2021-1586-01 Moderate: GNOME Update

red hat
Calendar Grey May 18, 2021
Dist Redhat Esm H88
Fedora's notice highlights a significant KDE update that resolves vulnerabilities and improves functionality.
An update for GNOME is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

GDM must be restarted for this update to take effect.

Summary

GNOME is the default desktop environment of Red Hat Enterprise Linux.
The following packages have been upgraded to a later upstream version: accountsservice (0.6.55), webkit2gtk3 (2.30.4). (BZ#1846376, BZ#1883304)
Security Fix(es):
* webkitgtk: type confusion may lead to arbitrary code execution (CVE-2020-9948)
* webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-9951)
* webkitgtk: out-of-bounds write may lead to code execution (CVE-2020-9983)
* webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-13543)
* webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-13584)
* glib2: insecure permissions for files and directories (CVE-2019-13012)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.4 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2019-13012 https://access.redhat.com/security/cve/CVE-2020-9948 https://access.redhat.com/security/cve/CVE-2020-9951 https://access.redhat.com/security/cve/CVE-2020-9983 https://access.redhat.com/security/cve/CVE-2020-13543 https://access.redhat.com/security/cve/CVE-2020-13584 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: OpenEXR-2.2.0-12.el8.src.rpm accountsservice-0.6.55-1.el8.src.rpm atkmm-2.24.2-7.el8.src.rpm cairomm-1.12.0-8.el8.src.rpm chrome-gnome-shell-10.1-7.el8.src.rpm dleyna-core-0.6.0-3.el8.src.rpm dleyna-server-0.6.0-3.el8.src.rpm enchant2-2.2.3-3.el8.src.rpm gdm-3.28.3-39.el8.src.rpm geoclue2-2.5.5-2.el8.src.rpm geocode-glib-3.26.0-3.el8.src.rpm gjs-1.56.2-5.el8.src.rpm glibmm24-2.56.0-2.el8.src.rpm gnome-boxes-3.36.5-8.el8.src.rpm gnome-control-center-3.28.2-27.el8.src.rpm gnome-online-accounts-3.28.2-2.el8.src.rpm gnome-photos-3.28.1-4.el8.src.rpm gnome-settings-daemon-3.32.0-14.el8.src.rpm gnome-shell-3.32.2-30.el8.src.rpm gnome-shell-extensions-3.32.1-14.el8.src.rpm gnome-software-3.36.1-5.el8.src.rpm gnome-terminal-3.28.3-3.el8.src.rpm gtk2-2.24.32-5.el8.src.rpm gtkmm24-2.24.5-6.el8.src.rpm gtkmm30-3.22.2-3.el8.src.rpm gvfs-1.36.2-11.el8.src.rpm libdazzle-3.28.5-2.el8.src.rpm libepubgen-0.1.0-3.el8.src.rpm libsigc++20-2.10.0-6.el8.src.rpm libvisual-0.4.0-25.el8.src.rpm mutter-3.32.2-57.el8.src.rpm nautilus-3.28.1-15.el8.src.rpm pangomm-2.40.1-6.el8.src.rpm soundtouch-2.0.0-3.el8.src.rpm webkit2gtk3-2.30.4-1.el8.src.rpm woff2-1.0.2-5.el8.src.rpm
aarch64: OpenEXR-debuginfo-2.2.0-12.el8.aarch64.rpm

Read the Full Advisory


Advisory ID: RHSA-2021:1586-01
Product: Red Hat Enterprise Linux
Issue date: 2021-05-18

Topic

An update for GNOME is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat CodeReady Linux Builder (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64

Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64

Bugs Fixed

837035 - Shortcuts -- alfanumeric vs numpad

1152037 - RFE: use virtio-scsi disk bus with discard='unmap' for guests that support it

1464902 - Crash in dls_async_task_complete

1671761 - Adding new workspaces is broken in gnome session under wayland

1700002 - adding several printers is stalling the printer plugin in GSD

1705392 - Changing screen resolution while recording screen will break the video.

1728632 - CVE-2019-13012 glib2: insecure permissions for files and directories

1728896 - glib2: 'keyfile' backend for gsettings not loaded

1765627 - Can't install both gnome-online-accounts-devel.i686 and gnome-online-accounts-devel.x86_64 on RHEL 8.1

1786496 - gnome-shell killed by SIGABRT in g_assertion_message_expr.cold.16()

1796916 - Notification appears with incorrect "system not registered - register to get updates" message on RHEL8.2 when locale is non-English

1802105 - rpm based extensions in RHEL8 should not receive updates from extensions.gnome.org

1833787 - Unable to disable onscreen keyboard in touch screen machine

1842229 - double-touch desktop icons fails sometimes

1845660 - JS WARNING from gnome-shell [MetaWindowX11]

1846376 - rebase accountsservice to latest release

1854290 - Physical device fails to wakeup via org.gnome.ScreenSaver D-Bus API

1860946 - gnome-shell logs AuthList property defined with 'let' or 'const'

1861357 - Login shows Exclamation Sign with no message for Caps Lock on

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here