RHSA-2026:54634: Important: webkit2gtk3 security update
Important: webkit2gtk3 security update
Other sources
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.Security Fix(es): Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712) webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720) webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731) webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734) webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/webkit2gtk3to a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4 - Upgrade
Upgrade
redhat/webkit2gtk3-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4 - Upgrade
Upgrade
redhat/webkit2gtk3-jscto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4 - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4 - Upgrade
Upgrade
redhat/webkit2gtk3-debugsourceto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4 - Upgrade
Upgrade
redhat/webkit2gtk3to a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4.aa - Upgrade
Upgrade
redhat/webkit2gtk3-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4.aa - Upgrade
Upgrade
redhat/webkit2gtk3-devel-debuginfoto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4.aa - Upgrade
Upgrade
redhat/webkit2gtk3-jscto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4.aa - Upgrade
Upgrade
redhat/webkit2gtk3-jsc-develto a version that resolves this vulnerability.Fixed in 2.52.5-1.el9_4.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54634?
The severity of RHSA-2026:54634 is high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:54634?
RHSA-2026:54634 addresses vulnerabilities including arbitrary JavaScript execution in PDF.js (CVE-2024-4367) and issues that may cause unexpected process crashes.
How do I fix RHSA-2026:54634?
To fix RHSA-2026:54634, it is recommended to update the affected packages webkit2gtk3 and its related development packages.
What is WebKitGTK and its relevance in RHSA-2026:54634?
WebKitGTK is a port of the WebKit rendering engine for GTK platforms, and it is crucial for displaying web content securely.
Which systems are affected by RHSA-2026:54634?
RHSA-2026:54634 affects various Red Hat Enterprise Linux systems including those for IBM z Systems and ARM 64.