Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:69098

Опубликовано: 22 сент. 2026
Источник: rocky
Оценка: Important

Описание

Important: webkit2gtk3 security update

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)

  • chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)

  • chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)

  • chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)

  • chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)

  • webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)

  • webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)

  • webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)

  • webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)

  • webkitgtk: use-after-free of JSCValue function parameters (CVE-2026-78376)

  • chromium-browser: Skia: Information disclosure via out-of-bounds read in crafted media file (CVE-2026-79020)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43795)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-64715)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64718)

  • webkitgtk: Visiting a maliciously crafted website may leak sensitive data (CVE-2026-64778)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64779)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64780)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64782)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64784)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65331)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65332)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65334)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65335)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65336)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65337)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65338)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65340)

  • webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2026-65341)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65351)

  • webkitgtk: Validate the full FeatureList array once in OpenTypeVerticalData findFeature (CVE-2026-83596)

  • chromium-browser: skia: chromium-browser: Information leak in Skia (CVE-2026-84359)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-84635)

  • webkitgtk: Processing maliciously crafted web content may disclose sensitive user information (CVE-2026-64753)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
webkit2gtk3aarch641.el9_8webkit2gtk3-2.54.0-1.el9_8.aarch64.rpm
webkit2gtk3-develaarch641.el9_8webkit2gtk3-devel-2.54.0-1.el9_8.aarch64.rpm
webkit2gtk3-jscaarch641.el9_8webkit2gtk3-jsc-2.54.0-1.el9_8.aarch64.rpm
webkit2gtk3-jsc-develaarch641.el9_8webkit2gtk3-jsc-devel-2.54.0-1.el9_8.aarch64.rpm
webkit2gtk3i6861.el9_8webkit2gtk3-2.54.0-1.el9_8.i686.rpm
webkit2gtk3x86_641.el9_8webkit2gtk3-2.54.0-1.el9_8.x86_64.rpm
webkit2gtk3-develi6861.el9_8webkit2gtk3-devel-2.54.0-1.el9_8.i686.rpm
webkit2gtk3-develx86_641.el9_8webkit2gtk3-devel-2.54.0-1.el9_8.x86_64.rpm
webkit2gtk3-jsci6861.el9_8webkit2gtk3-jsc-2.54.0-1.el9_8.i686.rpm
webkit2gtk3-jscx86_641.el9_8webkit2gtk3-jsc-2.54.0-1.el9_8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
redhat
около 2 лет назад

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
около 2 лет назад

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
debian
около 2 лет назад

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5 ...

CVSS3: 9.6
github
около 2 лет назад

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость графической библиотеки Skia браузера Google Chrome, позволяющая нарушителю выполнить выход из изолированной программной среды