Well I'm sorry to see that Valve are closing bug reports for security exploits on spurious grounds. The bug report was clear that this is an exploit reported by SELinux but the exploit has nothing to do with SELinux and is open on the target platform Ubuntu.
Of the 2 bugs you listed; #43 was closed as a Fedora bug with no further action, and #88 was a separate execheap bug in Webkit that was reported upstream and that they are dealing with.
Since Valve are doing nothing about this I will have to report it to other parties whose security this may affect.
Both the issues are in 3rd party toolkits Valve uses, libcef & libmiles, and they have explained in the other bugs why they are used. Please comment further on those other bugs, thank you.
Nothing extracted yet.
Steam, HL2 & TF2 have a security bug which could be exploited to inject code and execute it. They use writeable and executable heap memory this is a very bad thing, and would be forbidden on Windows under Data Execution Prevention (DEP).
hl_linux makes a call:
This is a bug and should be fixed!
This exploit is currently open on ALL Linux distributions WITHOUT SELinux including Ubuntu.
Report for Half Life 1:
and for Team Fortress 2: