Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:42062: Important: webkit2gtk3 security update

Red Hat has issued an Important security update for the webkit2gtk3 package in RHEL 9, addressing multiple vulnerabilities including arbitrary JavaScript execution in PDF.js (CVE-2024-4367, CVSS 8.8) and numerous WebKitGTK flaws that can lead to process crashes, memory corruption, sandbox escapes, and data disclosure via malicious web content. The vulnerabilities are fixed in the updated webkit2gtk3 packages provided by this advisory; specific fixed version numbers for the RHEL package are not detailed in the provided text. Administrators should apply the update promptly to mitigate risks of remote code execution, system instability, and information leakage.
Read Full Article →

Red Hat Product Errata RHSA-2026:42062 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:42062 - Security Advisory Overview Updated Packages Synopsis Important: webkit2gtk3 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712) webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720) webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731) webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734) webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2280382 - CVE-2024-4367 Mozilla: Arbitrary JavaScript execution in PDF.js BZ - 2500519 - CVE-2026-39872 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500520 - CVE-2026-43663 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500521 - CVE-2026-43676 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500522 - CVE-2026-43699 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500523 - CVE-2026-43701 webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox BZ - 2500524 - CVE-2026-43705 webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption BZ - 2500525 - CVE-2026-43707 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500526 - CVE-2026-43712 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500527 - CVE-2026-43713 webkitgtk: webkitgtk: Visiting a website may leak sensitive data BZ - 2500528 - CVE-2026-43715 webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption BZ - 2500529 - CVE-2026-43716 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500530 - CVE-2026-43720 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500531 - CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data BZ - 2500532 - CVE-2026-43725 webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox BZ - 2500533 - CVE-2026-43726 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500534 - CVE-2026-43727 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500535 - CVE-2026-43731 webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption BZ - 2500536 - CVE-2026-43732 webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information BZ - 2500537 - CVE-2026-43734 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500538 - CVE-2026-43740 webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory BZ - 2500539 - CVE-2026-43742 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500540 - CVE-2026-43745 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVEs CVE-2024-4367 CVE-2026-39872 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM webkit2gtk3-2.52.5-1.el9_8.src.rpm SHA-256: c141f7c4efe21af2afa5c7a375ccd93b3e2708082c21886154e199902c7961d6 x86_64 webkit2gtk3-2.52.5-1.el9_8.i686.rpm SHA-256: fe954f2669e552923b831d86a2657ed517d64f56bf1a2dd14da47ef004270ece webkit2gtk3-2.52.5-1.el9_8.x86_64.rpm SHA-256: a391fa486ede6258c94d01d9efb055a7363cb344be30713eccc6cdcee7a43f42 webkit2gtk3-debuginfo-2.52.5-1.el9_8.i686.rpm SHA-256: 190bd12d3fd5dc5c2bda3ade294e34c32d880585013f2ebbe2514ebd0631c487 webkit2gtk3-debuginfo-2.52.5-1.el9_8.x86_64.rpm SHA-256: a063321a36f1d1884606956184231a6683933519da6e8fb4a720878e61f162fa webkit2gtk3-debugsource-2.52.5-1.el9_8.i686.rpm SHA-256: d42c156568122842292c9d566306a503056184e8c6378db32ef0fd36d8b56ddc webkit2gtk3-debugsource-2.52.5-1.el9_8.x86_64.rpm SHA-256: c06a34c505b31d7eb0232e9751a39f394a94196e4a81026ae4200e8ea2b63700 webkit2gtk3-devel-2.52.5-1.el9_8.i686.rpm SHA-256: 306b96e6d2da67308f28f378959fb854e5bbd872dad8e91597ad69e9f4fd94f2 webkit2gtk3-devel-2.52.5-1.el9_8.x86_64.rpm SHA-256: f4a1feeac402ef9face9d8dfe4a30b5a6ac444862c1dab931286309e2dcde299 webkit2gtk3-devel-debuginfo-2.52.5-1.el9_8.i686.rpm SHA-256: 3d5e793bc87df91726f25083470126c8d17821b634cfe419ea46b7de1fc3c8f8 webkit2gtk3-devel-debuginfo-2.52.5-1.el9_8.x86_64.rpm SHA-256: 652fe0e1436e9f5009ce7f42ea606229b88c8e565a85edd759f0bb0c3892c4ff webkit2gtk3-jsc-2.52.5-1.el9_8.i686.rpm SHA-256: ebecc906ece103ad36d74117cba5da85d202b8b344d55ba49f1e0ff30ef51db3 webkit2gtk3-jsc-2.52.5-1.el9_8.x86_64.rpm SHA-256: e779f2f02b2e363f0ffebd42cb38227ab584ff985ec4ea18297a5e241eec2d89 webkit2gtk3-jsc-debuginfo-2.52.5-1.el9_8.i686.rpm SHA-256: 198d4da4e90ef3f68dc330acf52c2bfde3d49189e93c3cb882f7cf09b9d303da webkit2gtk3-jsc-debuginfo-2.52.5-1.el9_8.x86_64.rpm SHA-256: e851c024f5be551270c8b12018b12de0c336f5c533da29bcb5243d7b378550a2 webkit2gtk3-jsc-devel-2.52.5-1.el9_8.i686.rpm SHA-256: 148b92309436dd2255fc78e9fdb0ad5c605729f85ac69918d30916a938aba590 webkit2gtk3-jsc-devel-2.52.5-1.el9_8.x86_64.rpm SHA-256: 3c86ad9cf7f685794876da24fc60a5f79a556fd76302671f68e1d05b13e1066b webkit2gtk3-jsc-devel-debuginfo-2.

Share this article