[DSA 6463-1] webkit2gtk security update
Alberto Garcia <[email protected]>
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6463-1 [email protected] https://www.debian.org/security/ Alberto Garcia August 24, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit2gtk CVE ID : CVE-2026-43804 CVE-2026-64713 CVE-2026-64719 CVE-2026-64728 CVE-2026-64730 CVE-2026-64757 CVE-2026-64783 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that websites may know if the user has visited a given link. CVE-2026-64719 Shaheen Fazim discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-64728 An anonymous researcher discovered that maliciously crafted web content may violate iframe sandboxing policy. CVE-2026-64730 Kagami Rosylight discovered that visiting a website that frames malicious content may lead to UI spoofing. CVE-2026-64757 Milad Nasr and Nicholas Carlini discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-64783 lattice, Behzad Najjarpour Jabbari, Junyeong Lee, OGINOME Tomohito, Gia Bui and others discovered that processing maliciously crafted web content may lead to an unexpected process crash. For the stable distribution (trixie), these problems have been fixed in version 2.52.6-1~deb13u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/webkit2gtk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmqMZykACgkQAAyEYu0C 2AJ2KhAAir7bOkWMtgO6CchkAaKZxEuHZs7l/NFQT3rDJ4Q+3CbpbIc7jHeG7+8W u3zIVeG4F52BrE0DfRellXIvOdIlNGFiAcxC6bt//lHNoBEgx9GcKrjk8IacPMU2 MzWOhmSCgQGXXxdB3gt8p4pVaL33otYl/6hkVt/WePVHMqGPKsK+Cjf0YkrDB0gn yqx60uCYan4q2BMfpUy9ZmBkV07L5DllRmg+Knv7FOjxhWZyT6RvUKwbs1nFA0K/ qqtzrkbXzsSMcoFMYQSbvv7ry1zcc5genMcDHzWdNor89y5R0lM0V/k5AWdpiQL1 xXD3FbCkkSsH4D9NNrY0dmWf23TwK33qSCsytcJqEqYzHnHgyGy7aoOpy5wLUnPx P+TzSFyXyvtT8dvxCypTCxqRuxkMv/TGXkdVo0uRoHoUAJSJ9wBnIvaaCk1B6Htl PcAoDm6g6dpyBSMl4+5HS0ORQb4BmBWvNql5FzUABqmZ+tlyuRmFZvHH5590Obuh oJ1g0SuEKEglCy5KI1IP8rBTSsYl+sY0V6cxzKWMgJp1cBysn3ON0T6C4/hwnvt7 oJq8vbeufc9Fc6zEiitLCEzqllKrhP3GDKecjxozpLNqgZ4NaKcrOd72vevrDU32 6yXCd85Z+nyNkN25mYYA96tUT2cO9KEm9qpQzhWYz+MDA9QfhR8= =eaA6 -----END PGP SIGNATURE-----