Aggregator

webkitgtk-2.54.0-1.fc44

5 days 7 hours ago
FEDORA-2026-164300cb22 Packages in this update:
  • webkitgtk-2.54.0-1.fc44
Update description:

Update to 2.54.0:

  • Switch web process compositor to use Skia instead of TextureMapper.
  • Improved damage handling that is now also used during the composition to limit the composited areas.
  • Implement GPU atlas creation and replay substitution for batched raster image uploads.
  • Media capability reporting is more accurate.
  • Video decoding limits are now respected in media capabilities queries.
  • Add new improved API for page favicons.
  • Add magnification property to WebKitWebView to handle visual scaling.
  • Add new API to allow setting a per-navigation custom User-Agent to WebKitWebsitePolicies.
  • Remove the option to use cairo for 2D rendering.

WebKit Security fixes from 2.54.0: CVE-2026-84635, CVE-2026-64753, CVE-2026-64715, CVE-2026-64778, CVE-2026-64779, CVE-2026-64780, CVE-2026-64782, CVE-2026-64784, CVE-2026-65331, CVE-2026-65332, CVE-2026-65333, CVE-2026-65334, CVE-2026-65335, CVE-2026-65336, CVE-2026-65337, CVE-2026-65338, CVE-2026-65340, CVE-2026-65341, CVE-2026-65351, CVE-2026-78376, CVE-2026-83596.

WebKit security fixes from 2.52.6: CVE-2026-43804, CVE-2026-64713, CVE-2026-64728, CVE-2026-64730, CVE-2026-64757, CVE-2026-64783

This update also fixes a couple hundred or so ANGLE CVEs and several dozen Skia CVEs.

This update breaks some styles in Evolution and likely crashes Eclipse on startup. Sorry about that.

USN-8780-1: libsoup vulnerabilities

5 days 9 hours ago
It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was discovered that libsoup did not remove proxy authentication credentials when following HTTP redirects. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1539) Ahmed Lekssays discovered that libsoup incorrectly parsed certain HTTP requests. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-1801)

USN-8779-1: Bubblewrap vulnerabilities

5 days 10 hours ago
It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-12439) It was discovered that Bubblewrap incorrectly handled certain symlinks during sandbox setup. A local attacker could possibly use this issue to create files outside of the sandbox. (CVE-2026-87766)