Updated webkit2 packages fix security vulnerabilities
Publication date: 14 Nov 2025Modification date: 14 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-27838 , CVE-2024-27851 , CVE-2024-40776 , CVE-2024-40779 , CVE-2024-40780 , CVE-2024-40782 , CVE-2024-40789 , CVE-2024-4558
Description
CVE-2024-27838 A maliciously crafted webpage may be able to fingerprint
the user. Description: The issue was addressed by adding additional
logic.
CVE-2024-27851 Processing maliciously crafted web content may lead to
arbitrary code execution. Description: The issue was addressed with
improved bounds checks.
CVE-2024-40776 Processing maliciously crafted web content may lead to an
unexpected process crash. Description: A use-after-free issue was
addressed with improved memory management.
CVE-2024-40779 / CVE-2024-40780 Processing maliciously crafted web
content may lead to an unexpected process crash. Description: An
out-of-bounds read was addressed with improved bounds checking.
CVE-2024-40782 Processing maliciously crafted web content may lead to an
unexpected process crash. Description: A use-after-free issue was
addressed with improved memory management.
CVE-2024-40789 Processing maliciously crafted web content may lead to an
unexpected process crash. Description: An out-of-bounds access issue was
addressed with improved bounds checking.
CVE-2024-4558 Processing maliciously crafted web content may lead to an
unexpected process crash. Description: Use after free in ANGLE allowed a
remote attacker to potentially exploit heap corruption via a crafted
HTML page.
References
- https://bugs.mageia.org/show_bug.cgi?id=33513
- https://webkitgtk.org/release/webkitgtk-2.44.4.html
- https://webkitgtk.org/2024/08/13/webkitgtk2.44.3-released.html
- https://webkitgtk.org/security/WSA-2024-0004.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27838
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27851
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40776
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40779
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40780
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40782
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-40789
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4558
SRPMS
9/core
- webkit2-2.44.4-1.mga9