--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-826bf5a09a
2024-06-22 01:24:42.160550
--------------------------------------------------------------------------------

Name        : webkitgtk
Product     : Fedora 39
Version     : 2.44.2
Release     : 2.fc39
URL         : https://www.webkitgtk.org/
Summary     : GTK web content engine library
Description :
WebKitGTK is the port of the WebKit web rendering engine to the
GTK platform.

--------------------------------------------------------------------------------
Update Information:

Update to 2.44.2:
Make gamepads visible on axis movements, and not only on button presses.
Disable the gst-libav AAC decoder.
Make user scripts and style sheets visible in the Web Inspector.
Use the geolocation portal where available, with the existing geoclue as
fallback if the portal is not usable.
Use the printing portal when running sandboxed.
Use the file transfer portal for drag and drop when running sandboxed.
Avoid notifying an empty cursor rectangle to input methods.
Remove empty bar shown in detached inspector windows.
Consider keycode when activating application accelerators.
Fix several crashes and rendering issues.
Fix CVE-2024-27834
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jun  8 2024 Michael Catanzaro  - 2.44.2-2
- Add patch to fix excessive CPU usage
* Thu May 16 2024 Michael Catanzaro  - 2.44.2-1
- Update to 2.44.2
* Thu Apr 18 2024 Michael Catanzaro  - 2.44.1-2
- Request 4 GB of RAM per vCPU
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2282414 - CVE-2024-27834 webkitgtk: webkit: pointer authentication bypass [fedora-39]
        https://bugzilla.redhat.com/show_bug.cgi?id=2282414
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-826bf5a09a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
--
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue

Fedora 39: webkitgtk 2024-826bf5a09a Security Advisory Updates

June 22, 2024
Update to 2.44.2: Make gamepads visible on axis movements, and not only on button presses

Summary

WebKitGTK is the port of the WebKit web rendering engine to the

GTK platform.

Update Information:

Update to 2.44.2: Make gamepads visible on axis movements, and not only on button presses. Disable the gst-libav AAC decoder. Make user scripts and style sheets visible in the Web Inspector. Use the geolocation portal where available, with the existing geoclue as fallback if the portal is not usable. Use the printing portal when running sandboxed. Use the file transfer portal for drag and drop when running sandboxed. Avoid notifying an empty cursor rectangle to input methods. Remove empty bar shown in detached inspector windows. Consider keycode when activating application accelerators. Fix several crashes and rendering issues. Fix CVE-2024-27834

Change Log

* Sat Jun 8 2024 Michael Catanzaro - 2.44.2-2 - Add patch to fix excessive CPU usage * Thu May 16 2024 Michael Catanzaro - 2.44.2-1 - Update to 2.44.2 * Thu Apr 18 2024 Michael Catanzaro - 2.44.1-2 - Request 4 GB of RAM per vCPU

References

[ 1 ] Bug #2282414 - CVE-2024-27834 webkitgtk: webkit: pointer authentication bypass [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2282414

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-826bf5a09a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
Name : webkitgtk
Product : Fedora 39
Version : 2.44.2
Release : 2.fc39
URL : https://www.webkitgtk.org/
Summary : GTK web content engine library

Related News