Important: webkit2gtk3 security and bug fix update
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * webkitgtk: use-after-free issue leading to arbitrary code execution (CVE-2022-42826) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2023-23517) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2023-23518) * webkitgtk: buffer overflow issue was addressed with improved memory handling (CVE-2022-32886) * webkitgtk: out-of-bounds write issue was addressed with improved bounds checking (CVE-2022-32888) * webkitgtk: correctness issue in the JIT was addressed with improved checks (CVE-2022-32923) * webkitgtk: issue was addressed with improved UI handling (CVE-2022-42799) * webkitgtk: type confusion issue leading to arbitrary code execution (CVE-2022-42823) * webkitgtk: sensitive information disclosure issue (CVE-2022-42824) * webkitgtk: memory disclosure issue was addressed with improved memory handling (CVE-2022-42852) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2022-42863) * webkitgtk: use-after-free issue leading to arbitrary code execution (CVE-2022-42867) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2022-46691) * webkitgtk: Same Origin Policy bypass issue (CVE-2022-46692) * webkitgtk: logic issue leading to user information disclosure (CVE-2022-46698) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2022-46699) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2022-46700) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::addChild() (CVE-2023-25358) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::renderer() (CVE-2023-25360) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::setNextSibling() (CVE-2023-25361) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::repaintBlockSelectionGaps() (CVE-2023-25362) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::updateDescendantDependentFlags() (CVE-2023-25363) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * webkitgtk: use-after-free issue leading to arbitrary code execution (CVE-2022-42826) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2023-23517) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2023-23518) * webkitgtk: buffer overflow issue was addressed with improved memory handling (CVE-2022-32886) * webkitgtk: out-of-bounds write issue was addressed with improved bounds checking (CVE-2022-32888) * webkitgtk: correctness issue in the JIT was addressed with improved checks (CVE-2022-32923) * webkitgtk: issue was addressed with improved UI handling (CVE-2022-42799) * webkitgtk: type confusion issue leading to arbitrary code execution (CVE-2022-42823) * webkitgtk: sensitive information disclosure issue (CVE-2022-42824) * webkitgtk: memory disclosure issue was addressed with improved memory handling (CVE-2022-42852) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2022-42863) * webkitgtk: use-after-free issue leading to arbitrary code execution (CVE-2022-42867) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2022-46691) * webkitgtk: Same Origin Policy bypass issue (CVE-2022-46692) * webkitgtk: logic issue leading to user information disclosure (CVE-2022-46698) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2022-46699) * webkitgtk: memory corruption issue leading to arbitrary code execution (CVE-2022-46700) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::addChild() (CVE-2023-25358) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::renderer() (CVE-2023-25360) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::setNextSibling() (CVE-2023-25361) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::repaintBlockSelectionGaps() (CVE-2023-25362) * webkitgtk: heap-use-after-free in WebCore::RenderLayer::updateDescendantDependentFlags() (CVE-2023-25363) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2023:2256
- https://access.redhat.com/security/cve/CVE-2022-32886
- https://access.redhat.com/security/cve/CVE-2022-32888
- https://access.redhat.com/security/cve/CVE-2022-32923
- https://access.redhat.com/security/cve/CVE-2022-42799
- https://access.redhat.com/security/cve/CVE-2022-42823
- https://access.redhat.com/security/cve/CVE-2022-42824
- https://access.redhat.com/security/cve/CVE-2022-42826
- https://access.redhat.com/security/cve/CVE-2022-42852
- https://access.redhat.com/security/cve/CVE-2022-42863
- https://access.redhat.com/security/cve/CVE-2022-42867
- https://access.redhat.com/security/cve/CVE-2022-46691
- https://access.redhat.com/security/cve/CVE-2022-46692
- https://access.redhat.com/security/cve/CVE-2022-46698
- https://access.redhat.com/security/cve/CVE-2022-46699
- https://access.redhat.com/security/cve/CVE-2022-46700
- https://access.redhat.com/security/cve/CVE-2023-23517
- https://access.redhat.com/security/cve/CVE-2023-23518
- https://access.redhat.com/security/cve/CVE-2023-25358
- https://access.redhat.com/security/cve/CVE-2023-25360
- https://access.redhat.com/security/cve/CVE-2023-25361
- https://access.redhat.com/security/cve/CVE-2023-25362
- https://access.redhat.com/security/cve/CVE-2023-25363
- https://bugzilla.redhat.com/2128643
- https://bugzilla.redhat.com/2140501
- https://bugzilla.redhat.com/2140502
- https://bugzilla.redhat.com/2140503
- https://bugzilla.redhat.com/2140504
- https://bugzilla.redhat.com/2140505
- https://bugzilla.redhat.com/2156986
- https://bugzilla.redhat.com/2156987
- https://bugzilla.redhat.com/2156989
- https://bugzilla.redhat.com/2156990
- https://bugzilla.redhat.com/2156991
- https://bugzilla.redhat.com/2156992
- https://bugzilla.redhat.com/2156993
- https://bugzilla.redhat.com/2156994
- https://bugzilla.redhat.com/2167715
- https://bugzilla.redhat.com/2167716
- https://bugzilla.redhat.com/2167717
- https://bugzilla.redhat.com/2175099
- https://bugzilla.redhat.com/2175101
- https://bugzilla.redhat.com/2175103
- https://bugzilla.redhat.com/2175105
- https://bugzilla.redhat.com/2175107
- https://errata.almalinux.org/9/ALSA-2023-2256.html