[DSA 6398-1] webkit2gtk security update

Alberto Garcia <[email protected]> Thu, 23 Jul 2026 14:49:54 +0000
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6398-1                   [email protected]
https://www.debian.org/security/                           Alberto Garcia
July 23, 2026                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : webkit2gtk
CVE ID         : CVE-2024-4367 CVE-2026-28847 CVE-2026-28883 CVE-2026-28901
                 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905
                 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947
                 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-39872
                 CVE-2026-43658 CVE-2026-43660 CVE-2026-43663 CVE-2026-43676
                 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707
                 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716
                 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726
                 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734
                 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2024-4367

    Thomas Rinsma discovered that a type check was missing when
    handling fonts in PDF.js, which would allow arbitrary JavaScript
    execution in the PDF.js context.

CVE-2026-28847

    DARKNAVY, an anonymous researcher and Daniel Rhea discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.

CVE-2026-28883

    Kwak Kiyong discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.

CVE-2026-28901

    Joshua Rogers, Luigino Camastra, Igor Morgenstern, Guido Vranken,
    Maher Azzouzi and Ngan Nguyen discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.

CVE-2026-28902

    Tristan Madani and Nathaniel Oh discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.

CVE-2026-28903

    Mateusz Krzywicki discovered that processing maliciously crafted
    web content may lead to an unexpected process crash.

CVE-2026-28904

    Luka Racki discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.

CVE-2026-28905

    Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.

CVE-2026-28907

    Cantina discovered that processing maliciously crafted web content
    may prevent Content Security Policy from being enforced.

CVE-2026-28942

    Milad Nasr and Nicholas Carlini discovered that processing
    maliciously crafted web content may lead to an unexpected Safari
    crash.

CVE-2026-28946

    Gia Bui, dr3dd, and w0wbox discovered that processing maliciously
    crafted web content may lead to an unexpected Safari crash.

CVE-2026-28947

    dr3dd discovered that processing maliciously crafted web content
    may lead to an unexpected Safari crash.

CVE-2026-28953

    Maher Azzouzi discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.

CVE-2026-28955

    wac and Kookhwan Lee discovered that processing maliciously
    crafted web content may lead to an unexpected process crash.

CVE-2026-28958

    Cantina discovered that an app may be able to access sensitive
    user data.

CVE-2026-39872

    Utkarsh Pal and Ignacio Sanmillan discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.

CVE-2026-43658

    Do Young Park discovered that processing maliciously crafted web
    content may lead to an unexpected Safari crash.

CVE-2026-43660

    Cantina discovered that processing maliciously crafted web content
    may prevent Content Security Policy from being enforced.

CVE-2026-43663

    Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda,
    HexRabbit, NiNi, Tristan Madani and Brian Carpenter discovered
    that processing maliciously crafted web content may lead to an
    unexpected process crash.

CVE-2026-43676

    Mateusz Krzywicki, dr3dd, and Tommy DeVoss discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.

CVE-2026-43699

    Tommy DeVoss discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.

CVE-2026-43701

    Aaron Grattafiori discovered that a malicious website may be able
    to process restricted web content outside the sandbox.

CVE-2026-43705

    dr3dd discovered that processing maliciously crafted web content
    may lead to memory corruption.

CVE-2026-43707

    Amy Burnett discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.

CVE-2026-43712

    Kwak Kiyong, Song Nuri, and Tristan Madani discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.

CVE-2026-43713

    Jody Ritonga discovered that visiting a website may leak sensitive
    data.

CVE-2026-43715

    Milad Nasr and Nicholas Carlini discovered that processing
    maliciously crafted web content may lead to memory corruption.

CVE-2026-43716

    Tuan, Duc, Amy Burnett and Evan Lambert discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.

CVE-2026-43720

    Gia Bui and Josef Korbel discovered that processing maliciously
    crafted web content may lead to an unexpected process crash.

CVE-2026-43721

    Idan Masas discovered that a malicious website may be able to
    silently hijack clipboard data.

CVE-2026-43725

    Luke Francis discovered that a malicious website may be able to
    process restricted web content outside the sandbox.

CVE-2026-43726

    Josef Korbel, Tristan Madani, Gia Bui and Narendra Singh
    discovered that processing maliciously crafted web content may
    lead to an unexpected process crash.

CVE-2026-43727

    Tommy DeVoss, Gia Bui and Gurpreet Shergill discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.

CVE-2026-43731

    dr3dd discovered that processing maliciously crafted web content
    may lead to memory corruption.

CVE-2026-43732

    Nan Wang discovered that processing maliciously crafted web
    content may disclose sensitive user information.

CVE-2026-43734

    Jonathan Alush-Aben discovered that processing maliciously crafted
    web content may lead to an unexpected process crash.

CVE-2026-43740

    Nathaniel Oh and Arni Hardarson discovered that processing
    maliciously crafted web content may result in the disclosure of
    process memory.

CVE-2026-43742

    Yulia Mertsalova discovered that processing maliciously crafted
    web content may lead to an unexpected process crash.

CVE-2026-43745

    Amy Burnett and Khai Tran discovered that processing maliciously
    crafted web content may lead to an unexpected process crash.

For the stable distribution (trixie), these problems have been fixed in
version 2.52.5-1~deb13u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/webkit2gtk

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmpiJ84ACgkQAAyEYu0C
2AIX5Q/+P2jObjtbrSnLaBGr0SxCM+SQovrQjtkFQ5zWD+/KDfa4TVJK66j/KPmi
q2wrRr9vt3AzwyKKTlxTlzjQ8kCNU4QNaLkDOk/or+HRR17zfsiOzB29WAw+6Dqj
hsnYBodFqXB1V52aAEUKfOZKzuwFWiW1N2XVTPN5PWyd50ycjhxZASW57KNSxhPW
C7KsHrz97K8wGvyPFgQGkfLk8Y1YaBGNh6cB/kb8G0eoshH1E8Wd8jeKPD4oyOSt
vuC01712AvSKA9vk4tQUibx8L5scLUfzgHE/YiQE+TH6GdYLB1TW2cmiGMX1xPH5
sPz6phgM+gMZbEWJ3hHxmNCd1rfW+h/N4vRn32w6Fq+8CEni83WHLSZnwJ/cyeZe
fUNegJdflXvNJ+LZZS6zQS/dAdm5Wj/9o6LtcHwvpeTmRX15t1oCPy+39/GkK3SQ
GXLWvkYl8nmpQZgO45/7fjJYiJ0WnMQ8Q6ndaX/dNLeE+rTTsI3Gvn1HQCy6x8H4
/QCRnGQdZ/52WdsR367UKd+9oSCOxTlqlm1ip04m64TJSn73IknlAkkjG4jetTqJ
a5om+ARBa5KFUYwERrA/H7kkTyNki7WdipgHC5EWBPZY7o1pftN8N7CDgwUfrpY1
LQ/jnEXqddeE//HOK0GDdFyLLnQekM2J6crpVy20BL4BgLCYzPc=
=oqAn
-----END PGP SIGNATURE-----