Debian 10242 Published by

Debian GNU/Linux has undergone multiple security updates, which include webkit2gtk and needrestart regression updates:

Debian GNU/Linux 8 (Jessie), 9 (Stretch), and 10 (Buster) Extended LTS:
ELA-1238-2 needrestart regression update

Debian GNU/Linux 11 (Bulleye) LTS:
[DLA 3957-2] needrestart regression update

Debian GNU/Linux 12 (Bookworm):
[DSA 5823-1] webkit2gtk security update
[DSA 5815-2] needrestart regression update




[SECURITY] [DSA 5823-1] webkit2gtk security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5823-1 security@debian.org
https://www.debian.org/security/ Alberto Garcia
December 02, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : webkit2gtk
CVE ID : CVE-2024-44308 CVE-2024-44309

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2024-44308

Clement Lecigne and Benoit Sevens discovered that processing
maliciously crafted web content may lead to arbitrary code
execution. Apple is aware of a report that this issue may have
been actively exploited on Intel-based Mac systems.

CVE-2024-44309

Clement Lecigne and Benoit Sevens discovered that processing
maliciously crafted web content may lead to a cross site scripting
attack. Apple is aware of a report that this issue may have been
actively exploited on Intel-based Mac systems.

For the stable distribution (bookworm), these problems have been fixed in
version 2.46.4-1~deb12u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/webkit2gtk

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 3957-2] needrestart regression update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3957-2 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Salvatore Bonaccorso
December 02, 2024 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : needrestart
Version : 3.5-4+deb11u5
Debian Bug : 1087917 1087918 1087957 1087958 1088012 1088047

The update for needrestart announced as DLA 3957-1 introduced a
regression reporting false positives for processes running in chroot or
mountns. Updated packages are now available to correct this issue.

For Debian 11 bullseye, this problem has been fixed in version
3.5-4+deb11u5.

We recommend that you upgrade your needrestart packages.

For the detailed security status of needrestart please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/needrestart

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DSA 5815-2] needrestart regression update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5815-2 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
December 02, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : needrestart
Debian Bug : 1087917 1087918 1087957 1087958 1088012 1088047

The update for needrestart announced as DSA 5815-1 introduced a
regression reporting false positives for processes running in chroot or
mountns. Updated packages are now available to correct this issue.

For the stable distribution (bookworm), this problem has been fixed in
version 3.6-4+deb12u3.

We recommend that you upgrade your needrestart packages.

For the detailed security status of needrestart please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/needrestart

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


ELA-1238-2 needrestart regression update

Package : needrestart
Version : 1.2-8+deb8u4 (jessie), 2.11-3+deb9u4 (stretch), 3.4-5+deb10u3 (buster)

Related CVEs :
CVE-2024-48991

The update for needrestart announced as ELA 1228-1 introduced a
regression reporting false positives for processes running in chroot or
mountns. Updated packages are now available to correct this issue.

ELA-1238-2 needrestart regression update