Red Hat Product Errata RHSA-2026:54572 - Security Advisory Issued: 2026-08-13 Updated: 2026-08-13 RHSA-2026:54572 - Security Advisory Overview Updated Packages Synopsis Important: webkit2gtk3 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712) webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720) webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721) webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727) webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731) webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734) webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742) webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2280382 - CVE-2024-4367 Mozilla: Arbitrary JavaScript execution in PDF.js BZ - 2500519 - CVE-2026-39872 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500520 - CVE-2026-43663 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500521 - CVE-2026-43676 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500522 - CVE-2026-43699 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500523 - CVE-2026-43701 webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox BZ - 2500524 - CVE-2026-43705 webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption BZ - 2500525 - CVE-2026-43707 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500526 - CVE-2026-43712 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500527 - CVE-2026-43713 webkitgtk: webkitgtk: Visiting a website may leak sensitive data BZ - 2500528 - CVE-2026-43715 webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption BZ - 2500529 - CVE-2026-43716 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500530 - CVE-2026-43720 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500531 - CVE-2026-43721 webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data BZ - 2500532 - CVE-2026-43725 webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox BZ - 2500533 - CVE-2026-43726 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500534 - CVE-2026-43727 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500535 - CVE-2026-43731 webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption BZ - 2500536 - CVE-2026-43732 webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information BZ - 2500537 - CVE-2026-43734 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500538 - CVE-2026-43740 webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory BZ - 2500539 - CVE-2026-43742 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash BZ - 2500540 - CVE-2026-43745 webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVEs CVE-2024-4367 CVE-2026-39872 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM webkit2gtk3-2.52.5-1.el9_6.src.rpm SHA-256: 438d12e71b80306f3cc1f9411f3c6bc95a9de58a168eb6aa3dfcb2d98d333037 x86_64 webkit2gtk3-2.52.5-1.el9_6.i686.rpm SHA-256: fded7f5970c244fa0c31d2760e73579b572a1e71c09546503f8a1947806ea5e4 webkit2gtk3-2.52.5-1.el9_6.x86_64.rpm SHA-256: c4a6a63abb53d161741f18a367b7f8ba7cb99c86db96b1b5a3a0d56717445c71 webkit2gtk3-debuginfo-2.52.5-1.el9_6.i686.rpm SHA-256: 454ab3a4aec1ed2d521ccaf33d6b8fde6c446c0014705d6a9b289a06004de5f0 webkit2gtk3-debuginfo-2.52.5-1.el9_6.x86_64.rpm SHA-256: 6739a2a481e5ec0ded03c9d2298cd2deff1512e8202fff91ddb77c945a9d14e2 webkit2gtk3-debugsource-2.52.5-1.el9_6.i686.rpm SHA-256: b93e6da660b1c371c152da847a4ce904c645934ca697f3ef6f27ceec7c264af6 webkit2gtk3-debugsource-2.52.5-1.el9_6.x86_64.rpm SHA-256: 9a63ab2e65666eaa8e8b4d4eb628669e6c7eddb03368f17f4df2ae197fcee116 webkit2gtk3-devel-2.52.5-1.el9_6.i686.rpm SHA-256: 8d6544d275ac07158a4084d3aa6ec2fc3529b691bc46ba68b50541a215c25217 webkit2gtk3-devel-2.52.5-1.el9_6.x86_64.rpm SHA-256: 2fb9ed88a9871e2c47d2efe54e92752e691fb56e1a91d8b54ed64287457c7898 webkit2gtk3-devel-debuginfo-2.52.5-1.el9_6.i686.rpm SHA-256: 9982be80f9ce28c38a495bc3d9ac0e03c499492a6cf3f0a2e148e25e73cd4f8c webkit2gtk3-devel-debuginfo-2.52.5-1.el9_6.x86_64.rpm SHA-256: b31a95a712c7ceb11491975bdf93d58fa58b317cca7a2cc5396599da663551b1 webkit2gtk3-jsc-2.52.5-1.el9_6.i686.rpm SHA-256: 10ced38555075fcc71e8038716958fdacc4d3bb3996fddb0fe4207864d1431f8 webkit2gtk3-jsc-2.52.5-1.el9_6.x86_64.rpm SHA-256: d48bccbed032c64b7b62b97855ff93be1dbe6cd52cf82d266427802c5f466704 webkit2gtk3-jsc-debuginfo-2.52.5-1.el9_6.i686.rpm SHA-256: 4f440fd01710c30284875356de887fe7c38e011709974052dc951a2fa8e904a5 webkit2gtk3-jsc-debuginfo-2.52.5-1.el9_6.x86_64.rpm SHA-256: 4523159f554be66204bd6c561c71a747721b03255d5892017735c6792cd84c62 webkit2gtk3-jsc-devel-2.52.5-1.el9_6.i686.rpm SHA-256: 2962ad2d89f2d5013f8e6e5fb9210d65518c4e8195bec5b5a45732438580c237 webkit2gtk3-jsc-devel-2.52.5-1.el9_6.x86_64.rpm SHA-256: 020e5b4f86d18ec3b1bd215c4050b9cd7cce44d073c2021ccbe1d0d002a5aa9e webkit2gtk3-jsc-devel-debuginfo-2.52.5-1.el9_6.i686.rpm SHA-256: b00fb7c65eb2e930efcdc0e74b2a89658afd0f753335bcae18c301677c4a94fc web
This Red Hat Security Advisory addresses multiple vulnerabilities in the webkit2gtk3 package for RHEL 9.6 EUS, rated Important, including arbitrary JavaScript execution in PDF.js (CVE-2024-4367, CVSS 8.8) and numerous flaws allowing process crashes, memory corruption, sandbox escapes, and data disclosure via malicious web content. The article lists affected CVE identifiers but does not provide specific version ranges for the webkit2gtk3 package itself; the NVD data provided pertains to other software like Mozilla Firefox and Apple Safari, not the Red Hat package in question. Red Hat has released an update to remediate these issues, and administrators should apply the available webkit2gtk3 security update for their systems immediately.