{"id":257770,"date":"2026-09-25T12:20:21","date_gmt":"2026-09-25T09:20:21","guid":{"rendered":"https:\/\/digitrendz.blog\/z\/?p=257770"},"modified":"2026-09-25T12:20:21","modified_gmt":"2026-09-25T09:20:21","slug":"gnome-50-5-patch-fixes-gvfs-cve-and-epiphany-code-injection","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/tech-news\/257770\/gnome-50-5-patch-fixes-gvfs-cve-and-epiphany-code-injection\/","title":{"rendered":"GNOME 50.5 Patch Fixes gvfs CVE and Epiphany Code Injection"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; The GNOME Release Team shipped version 50.5 on September 24, updating 22 modules to address critical security vulnerabilities.<br>&#8211; Epiphany browser was updated to fix JavaScript injection flaws and a ZIP slip path traversal vulnerability in WebExtension files.<br>&#8211; The gvfs file system layer received a patch for CVE-2026-88924 by ensuring socket ownership is set correctly before creation.<br>&#8211; Memory safety issues were resolved in librsvg and GDM login manager, including use-after-free bugs that could crash sessions.<br>&#8211; Additional hardening measures were applied to GNOME Shell and libraries like libgsf and libsecret to prevent file handling exploits.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">T<\/mark>he <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/gnome-release-team\/\" class=\"acp-entity-link\" data-entity-id=\"301300\" data-entity-category=\"Organization\" title=\"Learn more about GNOME Release Team\" target=\"_blank\" rel=\"noopener noreferrer\">GNOME Release Team<\/a><\/strong> officially launched <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/gnome-50-5\/\" class=\"acp-entity-link\" data-entity-id=\"301301\" data-entity-category=\"product\" title=\"Learn more about GNOME 50.5\" target=\"_blank\" rel=\"noopener noreferrer\">GNOME 50.5<\/a><\/strong> on September 24, delivering a critical update that addresses several security vulnerabilities across its core ecosystem. This release updates 22 modules and targets specific flaws in the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/gvfs\/\" class=\"acp-entity-link\" data-entity-id=\"301302\" data-entity-category=\"Technology\" title=\"Learn more about gvfs\" target=\"_blank\" rel=\"noopener noreferrer\">gvfs<\/a><\/strong> file system layer, the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/epiphany\/\" class=\"acp-entity-link\" data-entity-id=\"301303\" data-entity-category=\"product\" title=\"Learn more about Epiphany\" target=\"_blank\" rel=\"noopener noreferrer\">Epiphany<\/a><\/strong> web browser, and the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/librsvg\/\" class=\"acp-entity-link\" data-entity-id=\"301304\" data-entity-category=\"Technology\" title=\"Learn more about librsvg\" target=\"_blank\" rel=\"noopener noreferrer\">librsvg<\/a><\/strong> image library. The team emphasized the urgency of these patches, stating, \u201cAll operating systems shipping GNOME 50 are encouraged to upgrade.\u201d Users relying on Epiphany for browsing, librsvg for viewing SVG images, or gvfs for file access remain vulnerable until their respective distributions integrate these new packages.<\/p>\n\n<h2 class=\"wp-block-heading\">Securing the Web Browser and File System<\/h2>\n\n<p class=\"wp-block-paragraph\">Epiphany advances from version 50.4 to 50.6 within this release cycle, incorporating two significant August updates. Version 50.6, released on August 13, resolves a <strong>JavaScript code injection<\/strong> vulnerability triggered by CSS selectors in the autofill feature. It also addresses a path traversal flaw in WebExtension XPI files known as <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/zipslip\/\" class=\"acp-entity-link\" data-entity-id=\"301306\" data-entity-category=\"Event\" title=\"Learn more about ZIPSLIP\" target=\"_blank\" rel=\"noopener noreferrer\">ZIPSLIP<\/a><\/strong>. In a ZIP slip attack, a maliciously crafted archive can write files outside its designated directory, potentially allowing an extension package to place files elsewhere on the disk. Additionally, version 50.5 introduces quoting mechanisms for command-line input before Epiphany passes it to the shell. Both versions also resolve crashes associated with the password manager and invalid bookmark imports.<\/p>\n\n<p class=\"wp-block-paragraph\">The <strong>gvfs<\/strong> component, specifically version 1.60.3, is the sole module assigned a Common Vulnerabilities and Exposures identifier in the release notes: <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/cve-2026-88924\/\" class=\"acp-entity-link\" data-entity-id=\"301305\" data-entity-category=\"law\" title=\"Learn more about CVE-2026-88924\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2026-88924<\/a><\/strong>. The remediation involves ensuring the admin backend sets ownership on its socket prior to creation. The changelog provides only a single line of description for this fix without assigning a severity score, leaving system administrators to assess the risk level based on that limited entry.<\/p>\n\n<h2 class=\"wp-block-heading\">Addressing Memory Corruption and Authentication Issues<\/h2>\n\n<p class=\"wp-block-paragraph\">Memory management errors were corrected in both the image rendering engine and the login manager. <strong>librsvg<\/strong> version 2.62.4 fixes a <strong>use-after-free<\/strong> bug, where a program continues to use memory that has already been released. This issue was triggered by duplicate XML entities found in nested XInclude documents. The librsvg update also incorporates updates to two Rust dependencies to address advisories <strong>RUSTSEC-2026-0187<\/strong> and <strong>RUSTSEC-2026-0204<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\">The display manager, <strong>GDM<\/strong> version 50.3, rectifies two use-after-free bugs. One of these defects could cause a complete user session crash during screen lock or unlock operations. GDM also repairs a regression caused by a previous security patch that inadvertently broke authentication on systemd. Meanwhile, <strong>GNOME Shell<\/strong> version 50.5 now prevents screen unlocking after a screen time limit expires and cancels mount password dialogs when the screen locks. It also validates serialized image data before creating a pixbuf.<\/p>\n\n<p class=\"wp-block-paragraph\">Further hardening efforts include updates to <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/libgsf\/\" class=\"acp-entity-link\" data-entity-id=\"301309\" data-entity-category=\"Technology\" title=\"Learn more about libgsf\" target=\"_blank\" rel=\"noopener noreferrer\">libgsf<\/a><\/strong> and <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/libsecret\/\" class=\"acp-entity-link\" data-entity-id=\"301310\" data-entity-category=\"Technology\" title=\"Learn more about libsecret\" target=\"_blank\" rel=\"noopener noreferrer\">libsecret<\/a><\/strong>. Version 1.14.59 of libgsf protects its OLE2 loader against runaway recursion and fixes zip reads on corrupted streams. The file backend for libsecret gains file locking capabilities to prevent concurrent writes from racing, ensuring data integrity during simultaneous access attempts.<\/p>\n\n<em>(Source: <a href='https:\/\/helpnetsecurity.com\/2026\/09\/24\/gnome-50-5-security-fixes\/' target='_blank'>Help Net Security<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>The GNOME Release Team launched version 50.5 on September 24 to address critical security vulnerabilities in core components like gvfs, Epiphany, and librsvg. Key fixes include patching JavaScript injection and ZIP slip flaws in the Epiphany browser, resolving a CVE in the gvfs file system layer,&#8230;<\/p>\n","protected":false},"author":1,"featured_media":257769,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,3327,3296,3254],"tags":[258276,258272,258273,258274,258275],"entities":[258285,258279,258282,258277,258278,258283,258280,258286,258281,258287,258284],"class_list":["post-257770","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-newswire","category-startups","category-technology","tag-epiphany","tag-gvfs","tag-libgsf","tag-librsvg","tag-zipslip","entity-cve-2026-88924","entity-epiphany","entity-gdm-50-3","entity-gnome-50-5","entity-gnome-release-team","entity-gnome-shell-50-5","entity-gvfs","entity-libgsf","entity-librsvg","entity-libsecret","entity-zipslip"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257770","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=257770"}],"version-history":[{"count":2,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257770\/revisions"}],"predecessor-version":[{"id":257796,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257770\/revisions\/257796"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/257769"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=257770"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=257770"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=257770"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=257770"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}