For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
GDM must be restarted for this update to take effect.
GNOME is the default desktop environment of Red Hat Enterprise Linux.
The following packages have been upgraded to a later upstream version:
accountsservice (0.6.55), webkit2gtk3 (2.30.4). (BZ#1846376, BZ#1883304)
Security Fix(es):
* webkitgtk: type confusion may lead to arbitrary code execution
(CVE-2020-9948)
* webkitgtk: use-after-free may lead to arbitrary code execution
(CVE-2020-9951)
* webkitgtk: out-of-bounds write may lead to code execution (CVE-2020-9983)
* webkitgtk: use-after-free may lead to arbitrary code execution
(CVE-2020-13543)
* webkitgtk: use-after-free may lead to arbitrary code execution
(CVE-2020-13584)
* glib2: insecure permissions for files and directories (CVE-2019-13012)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.4 Release Notes linked from the References section.
https://access.redhat.com/security/cve/CVE-2019-13012 https://access.redhat.com/security/cve/CVE-2020-9948 https://access.redhat.com/security/cve/CVE-2020-9951 https://access.redhat.com/security/cve/CVE-2020-9983 https://access.redhat.com/security/cve/CVE-2020-13543 https://access.redhat.com/security/cve/CVE-2020-13584 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/
Red Hat Enterprise Linux AppStream (v. 8):
Source:
OpenEXR-2.2.0-12.el8.src.rpm
accountsservice-0.6.55-1.el8.src.rpm
atkmm-2.24.2-7.el8.src.rpm
cairomm-1.12.0-8.el8.src.rpm
chrome-gnome-shell-10.1-7.el8.src.rpm
dleyna-core-0.6.0-3.el8.src.rpm
dleyna-server-0.6.0-3.el8.src.rpm
enchant2-2.2.3-3.el8.src.rpm
gdm-3.28.3-39.el8.src.rpm
geoclue2-2.5.5-2.el8.src.rpm
geocode-glib-3.26.0-3.el8.src.rpm
gjs-1.56.2-5.el8.src.rpm
glibmm24-2.56.0-2.el8.src.rpm
gnome-boxes-3.36.5-8.el8.src.rpm
gnome-control-center-3.28.2-27.el8.src.rpm
gnome-online-accounts-3.28.2-2.el8.src.rpm
gnome-photos-3.28.1-4.el8.src.rpm
gnome-settings-daemon-3.32.0-14.el8.src.rpm
gnome-shell-3.32.2-30.el8.src.rpm
gnome-shell-extensions-3.32.1-14.el8.src.rpm
gnome-software-3.36.1-5.el8.src.rpm
gnome-terminal-3.28.3-3.el8.src.rpm
gtk2-2.24.32-5.el8.src.rpm
gtkmm24-2.24.5-6.el8.src.rpm
gtkmm30-3.22.2-3.el8.src.rpm
gvfs-1.36.2-11.el8.src.rpm
libdazzle-3.28.5-2.el8.src.rpm
libepubgen-0.1.0-3.el8.src.rpm
libsigc++20-2.10.0-6.el8.src.rpm
libvisual-0.4.0-25.el8.src.rpm
mutter-3.32.2-57.el8.src.rpm
nautilus-3.28.1-15.el8.src.rpm
pangomm-2.40.1-6.el8.src.rpm
soundtouch-2.0.0-3.el8.src.rpm
webkit2gtk3-2.30.4-1.el8.src.rpm
woff2-1.0.2-5.el8.src.rpm
aarch64:
OpenEXR-debuginfo-2.2.0-12.el8.aarch64.rpm
Read the Full Advisory
An update for GNOME is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat CodeReady Linux Builder (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64
837035 - Shortcuts -- alfanumeric vs numpad
1152037 - RFE: use virtio-scsi disk bus with discard='unmap' for guests that support it
1464902 - Crash in dls_async_task_complete
1671761 - Adding new workspaces is broken in gnome session under wayland
1700002 - adding several printers is stalling the printer plugin in GSD
1705392 - Changing screen resolution while recording screen will break the video.
1728632 - CVE-2019-13012 glib2: insecure permissions for files and directories
1728896 - glib2: 'keyfile' backend for gsettings not loaded
1765627 - Can't install both gnome-online-accounts-devel.i686 and gnome-online-accounts-devel.x86_64 on RHEL 8.1
1786496 - gnome-shell killed by SIGABRT in g_assertion_message_expr.cold.16()
1796916 - Notification appears with incorrect "system not registered - register to get updates" message on RHEL8.2 when locale is non-English
1802105 - rpm based extensions in RHEL8 should not receive updates from extensions.gnome.org
1833787 - Unable to disable onscreen keyboard in touch screen machine
1842229 - double-touch desktop icons fails sometimes
1845660 - JS WARNING from gnome-shell [MetaWindowX11]
1846376 - rebase accountsservice to latest release
1854290 - Physical device fails to wakeup via org.gnome.ScreenSaver D-Bus API
1860946 - gnome-shell logs AuthList property defined with 'let' or 'const'
1861357 - Login shows Exclamation Sign with no message for Caps Lock on
Get the latest Linux and open source security news straight to your inbox.