Bug 8126 - [Anolis OS 8] Bugfix for CVE-2024-23222
Summary: [Anolis OS 8] Bugfix for CVE-2024-23222
Status: CONFIRMED
Alias: None
Product: Anolis OS 8
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: 8.6
Hardware: All Linux
: P2-High S2-major
Target Milestone: ---
Assignee: wangkaiqiang
QA Contact: shuming
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2024-02-01 10:29 UTC by 小龙
Modified: 2024-02-08 09:28 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2024-02-01 10:29:15 UTC
Description:
A type confusion issue was addressed with improved checks. This issue is fixed in tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.

Broken commit info:

Bugfix commit info:
http://seclists.org/fulldisclosure/2024/Jan/34
https://support.apple.com/en-us/HT214061
https://support.apple.com/en-us/HT214055
https://support.apple.com/en-us/HT214059
http://seclists.org/fulldisclosure/2024/Jan/37
http://seclists.org/fulldisclosure/2024/Jan/33
http://seclists.org/fulldisclosure/2024/Jan/38
https://support.apple.com/en-us/HT214058
http://seclists.org/fulldisclosure/2024/Jan/40
http://seclists.org/fulldisclosure/2024/Jan/36
https://support.apple.com/en-us/HT214057
https://support.apple.com/en-us/HT214063
http://seclists.org/fulldisclosure/2024/Jan/27
https://support.apple.com/en-us/HT214056
Comment 1 wangkaiqiang inspur_group 2024-02-08 09:28:47 UTC
This flaw depends on the WebKitGTK JIT engine to be enabled. This feature has been disabled in 2.38.5-1.0.5,by the errata ANSA-2023:0435 and ANSA-2023:0435