Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update to WebKitGTK 2.50.1: Improve text rendering performance. Fix audio playback broken on instagram. Fix rendering of layers with fractional transforms. Fix several crashes and rendering issues.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-04c193ecfe 2025-11-11 18:22:05.942504+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 41 Version : 2.50.1 Release : 1.fc41 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Update to WebKitGTK 2.50.1: Improve text rendering performance. Fix audio playback broken on instagram. Fix rendering of layers with fractional transforms. Fix several crashes and rendering issues. Fix CVE-2025-43343 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 13 2025 Michael Catanzaro - 2.50.1-1 - Update to 2.50.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-04c193ecfe' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. (CVE-2025-43965) In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order). (CVE-2025-46393) . MGASA-2025-0141 - Updated imagemagick packages fix security vulnerabilities Publication date: 01 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0141.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-43965, CVE-2025-46393 In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used. (CVE-2025-43965) In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order). (CVE-2025-46393) References: - https://bugs.mageia.org/show_bug.cgi?id=34225 - https://lists.fedoraproject.org/archives/list/
Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-57805565ad 2025-03-01 01:38:57.010325+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 40 Version : 2.46.6 Release : 1.fc40 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 11 2025 Michael Catanzaro - 2.46.6-1 - Update to WebKitGTK 2.46.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2344951 - CVE-2024-54543 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344951 [ 2 ] Bug #2344953 - CVE-2025-24162 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344953 [ 3 ] Bug #2344964 - CVE-2025-24143 webkitgtk: A maliciously crafted webpage may be able to fingerprint the user [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344964 [ 4 ] Bug #2344967 - CVE-2025-24150 webkitgtk: Copying a URL from Web Inspector may lead to command injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344967 [ 5 ] Bug #2344969 - CVE-2025-24158 webkitgtk: Processing web content may lead to a denial-of-service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344969 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-57805565ad' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3e8ed13bf0 2025-02-15 02:35:33.711279+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 41 Version : 2.46.6 Release : 1.fc41 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 11 2025 Michael Catanzaro - 2.46.6-1 - Update to WebKitGTK 2.46.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2344951 - CVE-2024-54543 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344951 [ 2 ] Bug #2344953 - CVE-2025-24162 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344953 [ 3 ] Bug #2344964 - CVE-2025-24143 webkitgtk: A maliciously crafted webpage may be able to fingerprint the user [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344964 [ 4 ] Bug #2344967 - CVE-2025-24150 webkitgtk: Copying a URL from Web Inspector may lead to command injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344967 [ 5 ] Bug #2344969 - CVE-2025-24158 webkitgtk: Processing web content may lead to a denial-of-service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2344969 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3e8ed13bf0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.46.5: Fix several crashes and rendering issues. CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-32bc143584 2024-12-21 03:35:46.415774+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 41 Version : 2.46.5 Release : 1.fc41 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Update to 2.46.5: Fix several crashes and rendering issues. CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 18 2024 Michael Catanzaro - 2.46.5-1 - Update to 2.46.5 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-32bc143584' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix webkit_web_context_allow_tls_certificate_for_host to handle IPv6 URIs produced by SoupURI. Ignore stops with offset zero before last one when rendering gradients with cairo. Write bwrapinfo.json to disk for xdg-desktop-portal.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-97faaca23d 2024-02-09 01:23:46.863627 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 39 Version : 2.42.5 Release : 1.fc39 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Fix webkit_web_context_allow_tls_certificate_for_host to handle IPv6 URIs produced by SoupURI. Ignore stops with offset zero before last one when rendering gradients with cairo. Write bwrapinfo.json to disk for xdg-desktop-portal. Fix gamepads detection by correctly handling focused window in GTK4. Fix several crashes and rendering issues. Fix CVE-2024-23222, CVE-2024-23206, CVE-2024-23213 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 5 2024 Michael Catanzaro - 2.42.5-1 - Update to WebKitGTK 2.42.5 * Fri Dec 15 2023 Michael Catanzaro - 2.42.4-1 - Update to 2.42.4 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-97faaca23d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix several crashes and rendering issues Security fixes: CVE-2023-38133, CVE-2023-38572, CVE-2023-38592, CVE-2023-38594, CVE-2023-38595, CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-a479289864 2023-08-04 01:28:14.886684 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 38 Version : 2.40.5 Release : 1.fc38 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Fix several crashes and rendering issues Security fixes: CVE-2023-38133, CVE-2023-38572, CVE-2023-38592, CVE-2023-38594, CVE-2023-38595, CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611 -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 1 2023 Michael Catanzaro - 2.40.5-1 - Update to 2.40.5 * Fri Jul 21 2023 Michael Catanzaro - 2.40.4-1 - Update to 2.40.4 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a479289864' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
* Fix scrollbar jumping to top when drag released outside window in GTK 4. * Fix video rendering when GL is disabled. * Fix flickering on looped videos when starting again. * Fix CPU usage on autoplaying videos. * Choose amount of painting threads depending on available CPU cores on GTK 4. * Fix several crashes and rendering issues. * Fix CVE-2023-28204 and CVE-2023-32373.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-9e75e38b47 2023-06-03 02:42:54.801348 --------------------------------------------------------------------------------Name : webkitgtk Product : Fedora 38 Version : 2.40.2 Release : 1.fc38 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. --------------------------------------------------------------------------------Update Information: * Fix scrollbar jumping to top when drag released outside window in GTK 4. * Fix video rendering when GL is disabled. * Fix flickering on looped videos when starting again. * Fix CPU usage on autoplaying videos. * Choose amount of painting threads depending on available CPU cores on GTK 4. * Fix several crashes and rendering issues. * Fix CVE-2023-28204 and CVE-2023-32373. --------------------------------------------------------------------------------ChangeLog: * Tue May 30 2023 Michael Catanzaro - 2.40.2-1 - Update to 2.40.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2209229 - CVE-2023-28204 webkitgtk: an out-of-bounds read when processing malicious content [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2209229 [ 2 ] Bug #2209755 - [CISA Major Incident] CVE-2023-32373 webkitgtk: a use-after-free when processing maliciously crafted web content [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2209755 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-9e75e38b47' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.