[DSA 6398-1] webkit2gtk security update
Alberto Garcia <[email protected]> Thu, 23 Jul 2026 14:49:54 +0000
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6398-1 [email protected] https://www.debian.org/security/ Alberto Garcia July 23, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit2gtk CVE ID : CVE-2024-4367 CVE-2026-28847 CVE-2026-28883 CVE-2026-28901 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-39872 CVE-2026-43658 CVE-2026-43660 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-4367 Thomas Rinsma discovered that a type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. CVE-2026-28847 DARKNAVY, an anonymous researcher and Daniel Rhea discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28883 Kwak Kiyong discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28901 Joshua Rogers, Luigino Camastra, Igor Morgenstern, Guido Vranken, Maher Azzouzi and Ngan Nguyen discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28902 Tristan Madani and Nathaniel Oh discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28903 Mateusz Krzywicki discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28904 Luka Racki discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28905 Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28907 Cantina discovered that processing maliciously crafted web content may prevent Content Security Policy from being enforced. CVE-2026-28942 Milad Nasr and Nicholas Carlini discovered that processing maliciously crafted web content may lead to an unexpected Safari crash. CVE-2026-28946 Gia Bui, dr3dd, and w0wbox discovered that processing maliciously crafted web content may lead to an unexpected Safari crash. CVE-2026-28947 dr3dd discovered that processing maliciously crafted web content may lead to an unexpected Safari crash. CVE-2026-28953 Maher Azzouzi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28955 wac and Kookhwan Lee discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28958 Cantina discovered that an app may be able to access sensitive user data. CVE-2026-39872 Utkarsh Pal and Ignacio Sanmillan discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43658 Do Young Park discovered that processing maliciously crafted web content may lead to an unexpected Safari crash. CVE-2026-43660 Cantina discovered that processing maliciously crafted web content may prevent Content Security Policy from being enforced. CVE-2026-43663 Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit, NiNi, Tristan Madani and Brian Carpenter discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43676 Mateusz Krzywicki, dr3dd, and Tommy DeVoss discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43699 Tommy DeVoss discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43701 Aaron Grattafiori discovered that a malicious website may be able to process restricted web content outside the sandbox. CVE-2026-43705 dr3dd discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2026-43707 Amy Burnett discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43712 Kwak Kiyong, Song Nuri, and Tristan Madani discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43713 Jody Ritonga discovered that visiting a website may leak sensitive data. CVE-2026-43715 Milad Nasr and Nicholas Carlini discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2026-43716 Tuan, Duc, Amy Burnett and Evan Lambert discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43720 Gia Bui and Josef Korbel discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43721 Idan Masas discovered that a malicious website may be able to silently hijack clipboard data. CVE-2026-43725 Luke Francis discovered that a malicious website may be able to process restricted web content outside the sandbox. CVE-2026-43726 Josef Korbel, Tristan Madani, Gia Bui and Narendra Singh discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43727 Tommy DeVoss, Gia Bui and Gurpreet Shergill discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43731 dr3dd discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2026-43732 Nan Wang discovered that processing maliciously crafted web content may disclose sensitive user information. CVE-2026-43734 Jonathan Alush-Aben discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43740 Nathaniel Oh and Arni Hardarson discovered that processing maliciously crafted web content may result in the disclosure of process memory. CVE-2026-43742 Yulia Mertsalova discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-43745 Amy Burnett and Khai Tran discovered that processing maliciously crafted web content may lead to an unexpected process crash. For the stable distribution (trixie), these problems have been fixed in version 2.52.5-1~deb13u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/webkit2gtk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmpiJ84ACgkQAAyEYu0C 2AIX5Q/+P2jObjtbrSnLaBGr0SxCM+SQovrQjtkFQ5zWD+/KDfa4TVJK66j/KPmi q2wrRr9vt3AzwyKKTlxTlzjQ8kCNU4QNaLkDOk/or+HRR17zfsiOzB29WAw+6Dqj hsnYBodFqXB1V52aAEUKfOZKzuwFWiW1N2XVTPN5PWyd50ycjhxZASW57KNSxhPW C7KsHrz97K8wGvyPFgQGkfLk8Y1YaBGNh6cB/kb8G0eoshH1E8Wd8jeKPD4oyOSt vuC01712AvSKA9vk4tQUibx8L5scLUfzgHE/YiQE+TH6GdYLB1TW2cmiGMX1xPH5 sPz6phgM+gMZbEWJ3hHxmNCd1rfW+h/N4vRn32w6Fq+8CEni83WHLSZnwJ/cyeZe fUNegJdflXvNJ+LZZS6zQS/dAdm5Wj/9o6LtcHwvpeTmRX15t1oCPy+39/GkK3SQ GXLWvkYl8nmpQZgO45/7fjJYiJ0WnMQ8Q6ndaX/dNLeE+rTTsI3Gvn1HQCy6x8H4 /QCRnGQdZ/52WdsR367UKd+9oSCOxTlqlm1ip04m64TJSn73IknlAkkjG4jetTqJ a5om+ARBa5KFUYwERrA/H7kkTyNki7WdipgHC5EWBPZY7o1pftN8N7CDgwUfrpY1 LQ/jnEXqddeE//HOK0GDdFyLLnQekM2J6crpVy20BL4BgLCYzPc= =oqAn -----END PGP SIGNATURE-----