Hi,

You are receiving an AlmaLinux Security update email because you subscribed to 
receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2023-05-12

Summary:

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK 
platform.

Security Fix(es):

* webkitgtk: use-after-free issue leading to arbitrary code execution 
(CVE-2022-42826)
* webkitgtk: memory corruption issue leading to arbitrary code execution 
(CVE-2023-23517)
* webkitgtk: memory corruption issue leading to arbitrary code execution 
(CVE-2023-23518)
* webkitgtk: buffer overflow issue was addressed with improved memory handling 
(CVE-2022-32886)
* webkitgtk: out-of-bounds write issue was addressed with improved bounds 
checking (CVE-2022-32888)
* webkitgtk: correctness issue in the JIT was addressed with improved checks 
(CVE-2022-32923)
* webkitgtk: issue was addressed with improved UI handling (CVE-2022-42799)
* webkitgtk: type confusion issue leading to arbitrary code execution 
(CVE-2022-42823)
* webkitgtk: sensitive information disclosure issue (CVE-2022-42824)
* webkitgtk: memory disclosure issue was addressed with improved memory 
handling (CVE-2022-42852)
* webkitgtk: memory corruption issue leading to arbitrary code execution 
(CVE-2022-42863)
* webkitgtk: use-after-free issue leading to arbitrary code execution 
(CVE-2022-42867)
* webkitgtk: memory corruption issue leading to arbitrary code execution 
(CVE-2022-46691)
* webkitgtk: Same Origin Policy bypass issue (CVE-2022-46692)
* webkitgtk: logic issue leading to user information disclosure (CVE-2022-46698)
* webkitgtk: memory corruption issue leading to arbitrary code execution 
(CVE-2022-46699)
* webkitgtk: memory corruption issue leading to arbitrary code execution 
(CVE-2022-46700)
* webkitgtk: heap-use-after-free in WebCore::RenderLayer::addChild() 
(CVE-2023-25358)
* webkitgtk: heap-use-after-free in WebCore::RenderLayer::renderer() 
(CVE-2023-25360)
* webkitgtk: heap-use-after-free in WebCore::RenderLayer::setNextSibling() 
(CVE-2023-25361)
* webkitgtk: heap-use-after-free in 
WebCore::RenderLayer::repaintBlockSelectionGaps() (CVE-2023-25362)
* webkitgtk: heap-use-after-free in 
WebCore::RenderLayer::updateDescendantDependentFlags() (CVE-2023-25363)

For more details about the security issue(s), including the impact, a CVSS 
score, acknowledgments, and other related information, refer to the CVE page(s) 
listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release 
Notes linked from the References section.

Full details, updated packages, references, and other related information: 
https://errata.almalinux.org/9/ALSA-2023-2256.html

This message is automatically generated, please don’t reply. For further 
questions, please, contact us via the AlmaLinux community chat: 
https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on 
https://lists.almalinux.org.

Kind regards,
AlmaLinux Team

Reply via email to