[Solved] [SECURITY] [DSA 5823-1] webkit2gtk security update :

If none of the specific sub-forums seem right for your thread, ask here.
Post Reply
Message
Author
Fossy
df -h | participant
df -h | participant
Posts: 369
Joined: 2021-08-06 12:45
Has thanked: 35 times
Been thanked: 35 times

[Solved] [SECURITY] [DSA 5823-1] webkit2gtk security update :

#1 Post by Fossy »

Concerns :
[SECURITY] [DSA 5823-1] webkit2gtk security update :
For the stable distribution (bookworm), these problems have been fixed in
version 2.46.4-1~deb12u1.

All our laptops were updated without any problems, except for this one:

Code: Select all

scan@scan-x751lab:~$ inxi -Fxpmrz 
System:
  Kernel: 6.1.0-28-amd64 arch: x86_64 bits: 64 compiler: gcc v: 12.2.0
    Desktop: Cinnamon v: 5.6.8 Distro: Debian GNU/Linux 12 (bookworm)
Machine:
  Type: Laptop System: ASUSTeK product: X751LAB v: 1.0
    serial: <superuser required>
  Mobo: ASUSTeK model: X751LAB v: 1.0 serial: <superuser required>
    UEFI: American Megatrends v: X751LAB.507 date: 12/07/2015
Battery:
  ID-1: BAT0 charge: 33.7 Wh (96.8%) condition: 34.8/37.4 Wh (92.8%)
    volts: 14.4 min: 14.4 model: ASUSTeK ASUS Battery status: charging
Memory:
  RAM: total: 3.7 GiB used: 2.57 GiB (69.6%)
  RAM Report: permissions: Unable to run dmidecode. Root privileges
    required.
CPU:
  Info: dual core model: Intel Core i3-5005U bits: 64 type: MT MCP
    arch: Broadwell rev: 4 cache: L1: 128 KiB L2: 512 KiB L3: 3 MiB
  Speed (MHz): avg: 574 high: 799 min/max: 500/1900 cores: 1: 500 2: 500
    3: 500 4: 799 bogomips: 15977
  Flags: avx avx2 ht lm nx pae sse sse2 sse3 sse4_1 sse4_2 ssse3 vmx
Graphics:
  Device-1: Intel HD Graphics 5500 vendor: ASUSTeK driver: i915 v: kernel
    arch: Gen-8 bus-ID: 00:02.0
  Device-2: Realtek USB Camera type: USB driver: uvcvideo bus-ID: 1-6:3
  Display: x11 server: X.Org v: 1.21.1.7 with: Xwayland v: 22.1.9 driver: X:
    loaded: modesetting unloaded: fbdev,vesa dri: iris gpu: i915
    resolution: 1600x900~60Hz
  API: OpenGL v: 4.6 Mesa 22.3.6 renderer: Mesa Intel HD Graphics 5500 (BDW
    GT2) direct-render: Yes
Audio:
  Device-1: Intel Broadwell-U Audio vendor: ASUSTeK driver: snd_hda_intel
    v: kernel bus-ID: 00:03.0
  Device-2: Intel Wildcat Point-LP High Definition Audio vendor: ASUSTeK
    driver: snd_hda_intel v: kernel bus-ID: 00:1b.0
  API: ALSA v: k6.1.0-28-amd64 status: kernel-api
  Server-1: PipeWire v: 0.3.65 status: active
  Server-2: PulseAudio v: 16.1 status: off (using pipewire-pulse)
Network:
  Device-1: Qualcomm Atheros QCA9565 / AR9565 Wireless Network Adapter
    vendor: AzureWave driver: ath9k v: kernel bus-ID: 02:00.0
  IF: wlp2s0 state: up mac: <filter>
Bluetooth:
  Device-1: IMC Networks type: USB driver: btusb v: 0.8 bus-ID: 1-7:5
  Report: hciconfig ID: hci0 rfk-id: 1 state: up address: <filter> bt-v: 2.1
    lmp-v: 4.1
Drives:
  Local Storage: total: 232.89 GiB used: 31.96 GiB (13.7%)
  ID-1: /dev/sda vendor: Samsung model: SSD 860 EVO 250GB size: 232.89 GiB
Partition:
  ID-1: / size: 219.84 GiB used: 31.92 GiB (14.5%) fs: ext4 dev: /dev/sda2
  ID-2: /boot/efi size: 299.4 MiB used: 5.8 MiB (2.0%) fs: vfat
    dev: /dev/sda1
Swap:
  ID-1: swap-1 type: partition size: 8.17 GiB used: 32.8 MiB (0.4%)
    dev: /dev/sda3
Sensors:
  System Temperatures: cpu: 32.0 C pch: 28.5 C mobo: N/A
  Fan Speeds (RPM): cpu: 0
Repos:
  Packages: 2624
  Active apt repos in: /etc/apt/sources.list
    1: deb https://deb.debian.org/debian/ bookworm main contrib non-free non-free-firmware
    2: deb https://deb.debian.org/debian/ bookworm-updates main contrib non-free non-free-firmware
    3: deb https://security.debian.org/debian-security/ bookworm-security main contrib non-free non-free-firmware
  Active apt repos in: /etc/apt/sources.list.d/eid.list
    1: deb https://files.eid.belgium.be/debian bookworm main
Info:
  Processes: 206 Uptime: 9m Init: systemd target: graphical (5) Compilers:
  gcc: 12.2.0 Shell: Bash v: 5.2.15 inxi: 3.3.26
scan@scan-x751lab:~$ 
sudo apt update apparently does not pick up this update ??? :

Code: Select all

scan@scan-x751lab:~$ LANG=C sudo apt update
[sudo] password for scan: 
Hit:1 https://deb.debian.org/debian bookworm InRelease
Hit:2 https://deb.debian.org/debian bookworm-updates InRelease      
Hit:3 https://files.eid.belgium.be/debian bookworm InRelease        
Hit:4 https://security.debian.org/debian-security bookworm-security InRelease
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
All packages are up to date.
scan@scan-x751lab:~$
However, when I look in synaptics I see that regarding this, the active webkit2gtk packages have not been changed to the new versions ??? and it still lists the previous 2.46. 3-1-deb12u1 as the latest new and installed version ???

Should I be concerned about this and/or how can I correct this?
Advice please, thank you
Last edited by Fossy on 2024-12-06 20:08, edited 1 time in total.
ASUS GL753VD / X550LD / K54HR / X751LAB / X751LAB + VueScan
Bookworm12.8_Cinnamon / Calamares Single Boot installations
Firefox ESR / DuckDuckGo / Thunderbird / LibreOffice / GIMP / eID Software/VueScan

lindi
Debian Developer
Debian Developer
Posts: 598
Joined: 2022-07-12 14:10
Has thanked: 2 times
Been thanked: 117 times

Re: [SECURITY] [DSA 5823-1] webkit2gtk security update :

#2 Post by lindi »

Apt update does not update packages, it updates package lists. Use apt upgrade to update packages.

Fossy
df -h | participant
df -h | participant
Posts: 369
Joined: 2021-08-06 12:45
Has thanked: 35 times
Been thanked: 35 times

Re: [SECURITY] [DSA 5823-1] webkit2gtk security update :

#3 Post by Fossy »

lindi wrote: 2024-12-04 16:01 Apt update does not update packages, it updates package lists. Use apt upgrade to update packages.
same result :

Code: Select all

scan@scan-x751lab:~$ LANG=C sudo apt update && sudo apt upgrade 
[sudo] password for scan: 
Hit:1 https://security.debian.org/debian-security bookworm-security InRelease
Hit:2 https://deb.debian.org/debian bookworm InRelease                         
Hit:3 https://deb.debian.org/debian bookworm-updates InRelease                 
Hit:4 https://files.eid.belgium.be/debian bookworm InRelease
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
All packages are up to date.
Pakketlijsten worden ingelezen... Klaar
Boom van vereisten wordt opgebouwd... Klaar
De statusinformatie wordt gelezen... Klaar 
Opwaardering wordt doorgerekend... Klaar
0 opgewaardeerd, 0 nieuw geïnstalleerd, 0 te verwijderen en 0 niet opgewaardeerd.
scan@scan-x751lab:~$ 
Image
ASUS GL753VD / X550LD / K54HR / X751LAB / X751LAB + VueScan
Bookworm12.8_Cinnamon / Calamares Single Boot installations
Firefox ESR / DuckDuckGo / Thunderbird / LibreOffice / GIMP / eID Software/VueScan

User avatar
None1975
df -h | participant
df -h | participant
Posts: 1546
Joined: 2015-11-29 18:23
Location: Russia, Kaliningrad
Has thanked: 63 times
Been thanked: 90 times

Re: [SECURITY] [DSA 5823-1] webkit2gtk security update :

#4 Post by None1975 »

Fossy wrote: 2024-12-04 16:05
same result:
And why are you using LANG=C? That's really not necessary in a standard Debian system.
OS: Debian 12.4 Bookworm / DE: XFCE
Debian Wiki | DontBreakDebian, My config files on github

Fossy
df -h | participant
df -h | participant
Posts: 369
Joined: 2021-08-06 12:45
Has thanked: 35 times
Been thanked: 35 times

Re: [Solved] [SECURITY] [DSA 5823-1] webkit2gtk security update :

#5 Post by Fossy »

Solved ...2/3 days later after official release date of the update :roll: , but :D

Code: Select all

scan@scan-x751lab:~$ sudo apt update
[sudo] wachtwoord voor scan: 
Geraakt:1 https://deb.debian.org/debian bookworm InRelease
Geraakt:2 https://deb.debian.org/debian bookworm-updates InRelease
Geraakt:3 https://security.debian.org/debian-security bookworm-security InRelease
Geraakt:4 https://files.eid.belgium.be/debian bookworm InRelease
Pakketlijsten worden ingelezen... Klaar
Boom van vereisten wordt opgebouwd... Klaar
De statusinformatie wordt gelezen... Klaar 
8 pakketten kunnen opgewaardeerd worden. Voer 'apt list --upgradable' uit om ze te zien.
scan@scan-x751lab:~$ sudo apt list --upgradable
Bezig met oplijsten... Klaar
gir1.2-javascriptcoregtk-4.0/stable-security 2.46.4-1~deb12u1 amd64 [opwaardeerbaar van: 2.46.3-1~deb12u1]
gir1.2-webkit2-4.0/stable-security 2.46.4-1~deb12u1 amd64 [opwaardeerbaar van: 2.46.3-1~deb12u1]
libjavascriptcoregtk-4.0-18/stable-security 2.46.4-1~deb12u1 amd64 [opwaardeerbaar van: 2.46.3-1~deb12u1]
libjavascriptcoregtk-4.1-0/stable-security 2.46.4-1~deb12u1 amd64 [opwaardeerbaar van: 2.46.3-1~deb12u1]
librados2/stable-security 16.2.15+ds-0+deb12u1 amd64 [opwaardeerbaar van: 16.2.11+ds-2]
librbd1/stable-security 16.2.15+ds-0+deb12u1 amd64 [opwaardeerbaar van: 16.2.11+ds-2]
libwebkit2gtk-4.0-37/stable-security 2.46.4-1~deb12u1 amd64 [opwaardeerbaar van: 2.46.3-1~deb12u1]
libwebkit2gtk-4.1-0/stable-security 2.46.4-1~deb12u1 amd64 [opwaardeerbaar van: 2.46.3-1~deb12u1]
scan@scan-x751lab:~$ sudo apt upgrade
Pakketlijsten worden ingelezen... Klaar
Boom van vereisten wordt opgebouwd... Klaar
De statusinformatie wordt gelezen... Klaar 
Opwaardering wordt doorgerekend... Klaar
De volgende pakketten zullen opgewaardeerd worden:
  gir1.2-javascriptcoregtk-4.0 gir1.2-webkit2-4.0 libjavascriptcoregtk-4.0-18
  libjavascriptcoregtk-4.1-0 librados2 librbd1 libwebkit2gtk-4.0-37
  libwebkit2gtk-4.1-0
8 opgewaardeerd, 0 nieuw geïnstalleerd, 0 te verwijderen en 0 niet opgewaardeerd.
Er moeten 0 B/68,0 MB aan archieven opgehaald worden.
Na deze bewerking zal er 510 kB extra schijfruimte gebruikt worden.
Wilt u doorgaan? [J/n] j
(Database wordt ingelezen ... 214448 bestanden en mappen momenteel geïnstalleerd
.)
Uitpakken van .../0-gir1.2-webkit2-4.0_2.46.4-1~deb12u1_amd64.deb wordt voorbere
id...
Bezig met uitpakken van gir1.2-webkit2-4.0:amd64 (2.46.4-1~deb12u1) over (2.46.3
-1~deb12u1) ...
Uitpakken van .../1-gir1.2-javascriptcoregtk-4.0_2.46.4-1~deb12u1_amd64.deb word
t voorbereid...
Bezig met uitpakken van gir1.2-javascriptcoregtk-4.0:amd64 (2.46.4-1~deb12u1) ov
er (2.46.3-1~deb12u1) ...
Uitpakken van .../2-libwebkit2gtk-4.0-37_2.46.4-1~deb12u1_amd64.deb wordt voorbe
reid...
Bezig met uitpakken van libwebkit2gtk-4.0-37:amd64 (2.46.4-1~deb12u1) over (2.46
.3-1~deb12u1) ...
Uitpakken van .../3-libjavascriptcoregtk-4.0-18_2.46.4-1~deb12u1_amd64.deb wordt
 voorbereid...
Bezig met uitpakken van libjavascriptcoregtk-4.0-18:amd64 (2.46.4-1~deb12u1) ove
r (2.46.3-1~deb12u1) ...
Uitpakken van .../4-libwebkit2gtk-4.1-0_2.46.4-1~deb12u1_amd64.deb wordt voorber
eid...
Bezig met uitpakken van libwebkit2gtk-4.1-0:amd64 (2.46.4-1~deb12u1) over (2.46.
3-1~deb12u1) ...
Uitpakken van .../5-libjavascriptcoregtk-4.1-0_2.46.4-1~deb12u1_amd64.deb wordt 
voorbereid...
Bezig met uitpakken van libjavascriptcoregtk-4.1-0:amd64 (2.46.4-1~deb12u1) over
 (2.46.3-1~deb12u1) ...
Uitpakken van .../6-librbd1_16.2.15+ds-0+deb12u1_amd64.deb wordt voorbereid...
Bezig met uitpakken van librbd1 (16.2.15+ds-0+deb12u1) over (16.2.11+ds-2) ...
Uitpakken van .../7-librados2_16.2.15+ds-0+deb12u1_amd64.deb wordt voorbereid...
Bezig met uitpakken van librados2 (16.2.15+ds-0+deb12u1) over (16.2.11+ds-2) ...
Instellen van librados2 (16.2.15+ds-0+deb12u1) ...
Instellen van libjavascriptcoregtk-4.0-18:amd64 (2.46.4-1~deb12u1) ...
Instellen van gir1.2-javascriptcoregtk-4.0:amd64 (2.46.4-1~deb12u1) ...
Instellen van libjavascriptcoregtk-4.1-0:amd64 (2.46.4-1~deb12u1) ...
Instellen van librbd1 (16.2.15+ds-0+deb12u1) ...
Instellen van libwebkit2gtk-4.0-37:amd64 (2.46.4-1~deb12u1) ...
Instellen van libwebkit2gtk-4.1-0:amd64 (2.46.4-1~deb12u1) ...
Instellen van gir1.2-webkit2-4.0:amd64 (2.46.4-1~deb12u1) ...
Bezig met afhandelen van triggers voor libc-bin (2.36-9+deb12u9) ...
scan@scan-x751lab:~$ 
ASUS GL753VD / X550LD / K54HR / X751LAB / X751LAB + VueScan
Bookworm12.8_Cinnamon / Calamares Single Boot installations
Firefox ESR / DuckDuckGo / Thunderbird / LibreOffice / GIMP / eID Software/VueScan

jamessmith260996
Posts: 2
Joined: 2018-01-22 16:45

Re: [Solved] [SECURITY] [DSA 5823-1] webkit2gtk security update :

#6 Post by jamessmith260996 »

Hey there! It seems that update might not be in your mirrors at the moment. At other times it may take a while for all of the mirrors to update to the latest versions. You can try this to force-check for updates:

Now, run sudo apt update, once again to update your list of available packages.
Check for the webkit2gtk package specifically with:
bash
apt-cache policy webkit2gtk
This will depict showing the installed version as well as the available versions.

Fossy
df -h | participant
df -h | participant
Posts: 369
Joined: 2021-08-06 12:45
Has thanked: 35 times
Been thanked: 35 times

Re: [Solved] [SECURITY] [DSA 5823-1] webkit2gtk security update :

#7 Post by Fossy »

jamessmith260996 wrote: 2024-12-06 22:19 Hey there! It seems that update might not be in your mirrors at the moment. At other times it may take a while for all of the mirrors to update to the latest versions. You can try this to force-check for updates:

Now, run sudo apt update, once again to update your list of available packages.
Check for the webkit2gtk package specifically with:
bash
apt-cache policy webkit2gtk
This will depict showing the installed version as well as the available versions.
The upgrade to the latest version, as I indicated in the previous post, has now been successful according to the "normal" procedure.

What is remarkable in this story, however, is that on this specific laptop it often takes some time before updates and important updates are detected.

I looked it up again for this specific update: I received a notification by email on 2/12/2024 23:59 (Debian Security Advisory DSA-5823-1 security@debian.org
https://www.debian.org/security/ Alberto Garcia
December 02, 2024 https://www.debian.org/security/faq )

However, I could only update / upgrade on December the 6 ???

Not exceptional, mind you, as far as I can remember I had the same " problem " with the upgrade to kernel ...6.1.0-28-amd64 , it also took a few days before I could perform the upgrade on this laptop!

Hence this topic.
ASUS GL753VD / X550LD / K54HR / X751LAB / X751LAB + VueScan
Bookworm12.8_Cinnamon / Calamares Single Boot installations
Firefox ESR / DuckDuckGo / Thunderbird / LibreOffice / GIMP / eID Software/VueScan

Post Reply