SUSE has issued an advisory on July 22: https://lists.suse.com/pipermail/sle-updates/2024-July/036098.html
Whiteboard: (none) => MGA9TOOStatus comment: (none) => Patch available from upstream and openSUSESource RPM: (none) => gnome-shell-46.2-1.mga10.src.rpmCVE: (none) => CVE-2024-36472
I could not find a patch anywhere, following links.
Assignee: bugsquad => gnome
Ubuntu has issued an advisory on August 15: https://ubuntu.com/security/notices/USN-6963-1
Suggested advisory: ======================== The updated packages fix a security vulnerability: In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior. (CVE-2024-36472) References: https://lists.suse.com/pipermail/sle-updates/2024-July/036098.html https://ubuntu.com/security/notices/USN-6963-1 ======================== Updated packages in core/updates_testing: ======================== gnome-shell-44.2-1.2.mga9 gnome-shell-api_doc-44.2-1.2.mga9 from SRPM: gnome-shell-44.2-1.2.mga9.src.rpm
Whiteboard: MGA9TOO => (none)Version: Cauldron => 9Status: NEW => ASSIGNEDAssignee: gnome => qa-bugsStatus comment: Patch available from upstream and openSUSE => (none)Source RPM: gnome-shell-46.2-1.mga10.src.rpm => gnome-shell-44.2-1.1.mga9.src.rpmDepends on: (none) => 33198
Keywords: (none) => advisory
installed both packages: gnome-shell-44.2-1.2.mga9 gnome-shell-api_doc-44.2-1.2.mga9 reboot and login to x11 session logout and into a wayland session ff ok. .mp4 playback (totem) sound and video -ok
CC: (none) => westel
meant to add : x86_84 system
updated also glibc for this DE. seems ok.
MGA9-64, Gnome installed both packages and rebooted No issues to report. I will need to test Cinnamon as well.
CC: (none) => brtians1
nothing in cinnamon for gnomeshell
Does anyone have a 32-bit Gnome system that could be tested? I realize they would not be commonplace. If not, I will send this on as is.
CC: (none) => andrewsfarm
Validating.
CC: (none) => sysadmin-bugsWhiteboard: (none) => MGA9-64-OKKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0314.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED