Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:16056: Important: webkit2gtk3 security update

This Red Hat security advisory addresses multiple vulnerabilities in the webkit2gtk3 package for RHEL 8.4, rated Important, which can lead to denial-of-service, sandbox escape, cross-site scripting, and policy bypasses via malicious web content. The article lists numerous CVEs but does not provide specific CVSS scores, affected version ranges, or fixed version numbers for the webkit2gtk3 package itself. IT professionals should apply the referenced Red Hat update immediately to mitigate these risks.
Read Full Article →

Red Hat Product Errata RHSA-2026:16056 - Security Advisory Issued: 2026-05-11 Updated: 2026-05-11 RHSA-2026:16056 - Security Advisory Overview Updated Packages Synopsis Important: webkit2gtk3 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43213) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43214) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43457) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43511) webkitgtk: Processing maliciously crafted web content may disclose internal states of the app (CVE-2025-46299) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20608) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20635) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20636) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20644) webkitgtk: A remote attacker may be able to cause a denial-of-service (CVE-2026-20652) webkitgtk: A website may be able to track users through Safari web extensions (CVE-2026-20676) webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy (CVE-2026-20643) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20664) webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-20665) webkitgtk: A maliciously crafted webpage may be able to fingerprint the user (CVE-2026-20691) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28857) webkitgtk: A malicious website may be able to process restricted web content outside the sandbox (CVE-2026-28859) webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack (CVE-2026-28871) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2448781 - CVE-2025-43213 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2448782 - CVE-2025-43214 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2448786 - CVE-2025-43457 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2448787 - CVE-2025-43511 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2448788 - CVE-2025-46299 webkitgtk: Processing maliciously crafted web content may disclose internal states of the app BZ - 2448789 - CVE-2026-20608 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2448790 - CVE-2026-20635 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2448791 - CVE-2026-20636 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2448792 - CVE-2026-20644 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2448793 - CVE-2026-20652 webkitgtk: A remote attacker may be able to cause a denial-of-service BZ - 2448794 - CVE-2026-20676 webkitgtk: A website may be able to track users through Safari web extensions BZ - 2453000 - CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy BZ - 2453001 - CVE-2026-20664 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2453002 - CVE-2026-20665 webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced BZ - 2453003 - CVE-2026-20691 webkitgtk: A maliciously crafted webpage may be able to fingerprint the user BZ - 2453004 - CVE-2026-28857 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2453006 - CVE-2026-28859 webkitgtk: A malicious website may be able to process restricted web content outside the sandbox BZ - 2453008 - CVE-2026-28871 webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack CVEs CVE-2025-43213 CVE-2025-43214 CVE-2025-43457 CVE-2025-43511 CVE-2025-46299 CVE-2026-20608 CVE-2026-20635 CVE-2026-20636 CVE-2026-20643 CVE-2026-20644 CVE-2026-20652 CVE-2026-20664 CVE-2026-20665 CVE-2026-20676 CVE-2026-20691 CVE-2026-28857 CVE-2026-28859 CVE-2026-28871 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM webkit2gtk3-2.52.3-1.el8_4.src.rpm SHA-256: 7a473aba4295fba69f4174d0464e03477cd8438bd631e55bfb08b4da332f680f x86_64 webkit2gtk3-2.52.3-1.el8_4.i686.rpm SHA-256: a57e4ef2f240c1950dbd7840730b67b6a4474d83a440b901303855b2f435f834 webkit2gtk3-2.52.3-1.el8_4.x86_64.rpm SHA-256: 820a2456890f0420bf6d1c17af364bf394cf66c46adbd169c4c61f2ba5021089 webkit2gtk3-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 9c5e212a75e1820e275ac63965fbe16f6bbc61d75e6a1dec94a401c46439246f webkit2gtk3-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 2d38a3f4b9e91bd2230ac25becfb6f24812c9438adefd85ce4c3b064843265d4 webkit2gtk3-debugsource-2.52.3-1.el8_4.i686.rpm SHA-256: a66280a1370250a0ad00f8e700509c151b21f9e35c333ed09a2639d14bea1dcb webkit2gtk3-debugsource-2.52.3-1.el8_4.x86_64.rpm SHA-256: 87a3f2a4bf327682fac8d1e4bb53f755ac9f1d7c7690a9191349b9f2f07efff3 webkit2gtk3-devel-2.52.3-1.el8_4.i686.rpm SHA-256: 4584e6e446d43681557c4bdac5c56aa920df4f3846d196726bf71094a3ab7b82 webkit2gtk3-devel-2.52.3-1.el8_4.x86_64.rpm SHA-256: 1f46291724f37dc8a0e81cb493bd162fd869802adf24d2135f7962c94c7edb41 webkit2gtk3-devel-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 44db2f29f2ace067976db8b211aeba59ba666f1b08d7c38bfbcc2937e8c198a5 webkit2gtk3-devel-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 5579a14e6a85677c7ba24a35fde53e26e7ff60b6133d2ec6a9b667799359a349 webkit2gtk3-jsc-2.52.3-1.el8_4.i686.rpm SHA-256: ca69f9e76386a605199def3ba14a50add67427948517a99aa57d8331a07eed83 webkit2gtk3-jsc-2.52.3-1.el8_4.x86_64.rpm SHA-256: 0422f70339f3761d7fbc97d3840dd689ce5923967572c8e2c2a8cd5d642256d5 webkit2gtk3-jsc-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 8db1591fa122fccb4defac0753fa85a2ac07c32cceb21ddff7268efaca14a5e1 webkit2gtk3-jsc-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 052ea20145a3ca4d2f28c5526f0798b38cb18da7b32cfc057324beb663e0972c webkit2gtk3-jsc-devel-2.52.3-1.el8_4.i686.rpm SHA-256: 83d7e47b4feef649d55c8832139b47e2dca9c3d876ebce41a0539b38a1ff7d53 webkit2gtk3-jsc-devel-2.52.3-1.el8_4.x86_64.rpm SHA-256: 3aa5883907f2c6b3ed4336b42978d8b3790ead027eab1e793b5a729e3a615376 webkit2gtk3-jsc-devel-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 0f80dbf0f261749569c9772e4416b0f6074eba42cd67442d6a8c816c42e4323c webkit2gtk3-jsc-devel-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 2a53191b3dc9d33263ac4feca07eb407ccb772938a131531b8a16ff00f0db86b Red Hat Enterprise Linux Server - AUS 8.4 SRPM webkit2gtk3-2.52.3-1.el8_4.src.rpm SHA-256: 7a473aba4295fba69f4174d0464e03477cd8438bd631e55bfb08b4da332f680f x86_64 webkit2gtk3-2.52.3-1.el8_4.i686.rpm SHA-256: a57e4ef2f240c1950dbd7840730b67b6a4474d83a440b901303855b2f435f834 webkit2gtk3-2.52.3-1.el8_4.x86_64.rpm SHA-256: 820a2456890f0420bf6d1c17af364bf394cf66c46adbd169c4c61f2ba5021089 webkit2gtk3-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 9c5e212a75e1820e275ac63965fbe16f6bbc61d75e6a1dec94a401c46439246f webkit2gtk3-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 2d38a3f4b9e91bd2230ac25becfb6f24812c9438adefd85ce4c3b064843265d4 webkit2gtk3-debugsource-2.52.3-1.el8_4.i686.rpm SHA-256: a66280a1370250a0ad00f8e700509c151b21f9e35c333ed09a2639d14bea1dcb webkit2gtk3-debugsource-2.52.3-1.el8_4.x86_64.rpm SHA-256: 87a3f2a4bf327682fac8d1e4bb53f755ac9f1d7c7690a9191349b9f2f07efff3 webkit2gtk3-devel-2.52.3-1.el8_4.i686.rpm SHA-256: 4584e6e446d43681557c4bdac5c56aa920df4f3846d196726bf71094a3ab7b82 webkit2gtk3-devel-2.52.3-1.el8_4.x86_64.rpm SHA-256: 1f46291724f37dc8a0e81cb493bd162fd869802adf24d2135f7962c94c7edb41 webkit2gtk3-devel-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 44db2f29f2ace067976db8b211aeba59ba666f1b08d7c38bfbcc2937e8c198a5 webkit2gtk3-devel-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 5579a14e6a85677c7ba24a35fde53e26e7ff60b6133d2ec6a9b667799359a349 webkit2gtk3-jsc-2.52.3-1.el8_4.i686.rpm SHA-256: ca69f9e76386a605199def3ba14a50add67427948517a99aa57d8331a07eed83 webkit2gtk3-jsc-2.52.3-1.el8_4.x86_64.rpm SHA-256: 0422f70339f3761d7fbc97d3840dd689ce5923967572c8e2c2a8cd5d642256d

Share this article