Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:42062

Опубликовано: 22 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: webkit2gtk3 security update

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699)

  • webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701)

  • webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712)

  • webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713)

  • webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720)

  • webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721)

  • webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727)

  • webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731)

  • webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734)

  • webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742)

  • webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
webkit2gtk3i6861.el9_8webkit2gtk3-2.52.5-1.el9_8.i686.rpm
webkit2gtk3x86_641.el9_8webkit2gtk3-2.52.5-1.el9_8.x86_64.rpm
webkit2gtk3-develi6861.el9_8webkit2gtk3-devel-2.52.5-1.el9_8.i686.rpm
webkit2gtk3-develx86_641.el9_8webkit2gtk3-devel-2.52.5-1.el9_8.x86_64.rpm
webkit2gtk3-jsci6861.el9_8webkit2gtk3-jsc-2.52.5-1.el9_8.i686.rpm
webkit2gtk3-jscx86_641.el9_8webkit2gtk3-jsc-2.52.5-1.el9_8.x86_64.rpm
webkit2gtk3-jsc-develi6861.el9_8webkit2gtk3-jsc-devel-2.52.5-1.el9_8.i686.rpm
webkit2gtk3-jsc-develx86_641.el9_8webkit2gtk3-jsc-devel-2.52.5-1.el9_8.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
3 дня назад

Security update for webkit2gtk3

rocky
10 дней назад

Important: webkit2gtk3 security update

oracle-oval
11 дней назад

ELSA-2026-42088: webkit2gtk3 security update (IMPORTANT)

oracle-oval
11 дней назад

ELSA-2026-42062: webkit2gtk3 security update (IMPORTANT)

CVSS3: 8.8
ubuntu
около 2 лет назад

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.