RHSA-2026:58550: Important: webkit2gtk3 security update
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.Security Fix(es): Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712) webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720) webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731) webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734) webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/webkit2gtk3to a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3-debugsourceto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3-devel-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3-jscto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-devel-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2 - Upgrade
Upgrade
redhat/webkit2gtk3to a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa - Upgrade
Upgrade
redhat/webkit2gtk3-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa - Upgrade
Upgrade
redhat/webkit2gtk3-debugsourceto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa - Upgrade
Upgrade
redhat/webkit2gtk3-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa - Upgrade
Upgrade
redhat/webkit2gtk3-devel-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa - Upgrade
Upgrade
redhat/webkit2gtk3-jscto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-devel-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_2.aa