RHSA-2026:54634HighCVSS 8.8

Red Hat Security Advisory: webkit2gtk3 security update

Published
August 13, 2026
Last Modified
August 13, 2026

🔗 CVE IDs covered (23)

📋 Description

CVE-2024-4367 — Mozilla: Arbitrary JavaScript execution in PDF.js CVE-2026-39872 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43663 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43676 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43699 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43701 — webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox CVE-2026-43705 — webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption CVE-2026-43707 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43712 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43713 — webkitgtk: webkitgtk: Visiting a website may leak sensitive data CVE-2026-43715 — webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption CVE-2026-43716 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43720 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43721 — webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data CVE-2026-43725 — webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox CVE-2026-43726 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43727 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43731 — webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption CVE-2026-43732 — webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information CVE-2026-43734 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43740 — webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory CVE-2026-43742 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash CVE-2026-43745 — webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash

🎯 Affected products47

  • Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-0:2.52.5-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-0:2.52.5-1.el9_4.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-0:2.52.5-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-0:2.52.5-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-0:2.52.5-1.el9_4.src as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-0:2.52.5-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debuginfo-0:2.52.5-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debuginfo-0:2.52.5-1.el9_4.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debuginfo-0:2.52.5-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debuginfo-0:2.52.5-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debuginfo-0:2.52.5-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debugsource-0:2.52.5-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debugsource-0:2.52.5-1.el9_4.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debugsource-0:2.52.5-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debugsource-0:2.52.5-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-debugsource-0:2.52.5-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-0:2.52.5-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-0:2.52.5-1.el9_4.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-0:2.52.5-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-0:2.52.5-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-0:2.52.5-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_4.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-jsc-0:2.52.5-1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-jsc-0:2.52.5-1.el9_4.i686 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • webkit2gtk3-jsc-0:2.52.5-1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
  • +17 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (26)