[Apollo] Advisories Statistics light light Login

RLSA-2026:42062

Security Mirrored from RHSA-2026:42062
Issued at: 2026-07-22
Updated at: 2026-07-23

Synopsis

Important: webkit2gtk3 security update



Description

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

* Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699)

* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701)

* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712)

* webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713)

* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720)

* webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721)

* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727)

* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731)

* webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734)

* webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742)

* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2280382 2500519 2500520 2500521 2500522 2500523 2500524 2500525 2500526 2500527 2500528 2500529 2500530 2500531 2500532 2500533 2500534 2500535 2500536 2500537 2500538 2500539 2500540

CVEs

CVE-2024-4367 CVE-2026-39872 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745

Affected packages

Rocky Linux 9 aarch64 - AppStream

webkit2gtk3-0:2.52.5-1.el9_8.aarch64.rpm webkit2gtk3-0:2.52.5-1.el9_8.src.rpm webkit2gtk3-debuginfo-0:2.52.5-1.el9_8.aarch64.rpm webkit2gtk3-debugsource-0:2.52.5-1.el9_8.aarch64.rpm webkit2gtk3-devel-0:2.52.5-1.el9_8.aarch64.rpm webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_8.aarch64.rpm webkit2gtk3-jsc-0:2.52.5-1.el9_8.aarch64.rpm webkit2gtk3-jsc-debuginfo-0:2.52.5-1.el9_8.aarch64.rpm webkit2gtk3-jsc-devel-0:2.52.5-1.el9_8.aarch64.rpm webkit2gtk3-jsc-devel-debuginfo-0:2.52.5-1.el9_8.aarch64.rpm

Rocky Linux 9 x86_64 - AppStream

webkit2gtk3-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-0:2.52.5-1.el9_8.src.rpm webkit2gtk3-0:2.52.5-1.el9_8.x86_64.rpm webkit2gtk3-debuginfo-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-debuginfo-0:2.52.5-1.el9_8.x86_64.rpm webkit2gtk3-debugsource-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-debugsource-0:2.52.5-1.el9_8.x86_64.rpm webkit2gtk3-devel-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-devel-0:2.52.5-1.el9_8.x86_64.rpm webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_8.x86_64.rpm webkit2gtk3-jsc-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-jsc-0:2.52.5-1.el9_8.x86_64.rpm webkit2gtk3-jsc-debuginfo-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-jsc-debuginfo-0:2.52.5-1.el9_8.x86_64.rpm webkit2gtk3-jsc-devel-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-jsc-devel-0:2.52.5-1.el9_8.x86_64.rpm webkit2gtk3-jsc-devel-debuginfo-0:2.52.5-1.el9_8.i686.rpm webkit2gtk3-jsc-devel-debuginfo-0:2.52.5-1.el9_8.x86_64.rpm

Rocky Linux 9 s390x - AppStream

webkit2gtk3-0:2.52.5-1.el9_8.src.rpm webkit2gtk3-0:2.52.5-1.el9_8.s390x.rpm webkit2gtk3-debuginfo-0:2.52.5-1.el9_8.s390x.rpm webkit2gtk3-debugsource-0:2.52.5-1.el9_8.s390x.rpm webkit2gtk3-devel-0:2.52.5-1.el9_8.s390x.rpm webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_8.s390x.rpm webkit2gtk3-jsc-0:2.52.5-1.el9_8.s390x.rpm webkit2gtk3-jsc-debuginfo-0:2.52.5-1.el9_8.s390x.rpm webkit2gtk3-jsc-devel-0:2.52.5-1.el9_8.s390x.rpm webkit2gtk3-jsc-devel-debuginfo-0:2.52.5-1.el9_8.s390x.rpm

Rocky Linux 9 ppc64le - AppStream

webkit2gtk3-0:2.52.5-1.el9_8.src.rpm webkit2gtk3-0:2.52.5-1.el9_8.ppc64le.rpm webkit2gtk3-debuginfo-0:2.52.5-1.el9_8.ppc64le.rpm webkit2gtk3-debugsource-0:2.52.5-1.el9_8.ppc64le.rpm webkit2gtk3-devel-0:2.52.5-1.el9_8.ppc64le.rpm webkit2gtk3-devel-debuginfo-0:2.52.5-1.el9_8.ppc64le.rpm webkit2gtk3-jsc-0:2.52.5-1.el9_8.ppc64le.rpm webkit2gtk3-jsc-debuginfo-0:2.52.5-1.el9_8.ppc64le.rpm webkit2gtk3-jsc-devel-0:2.52.5-1.el9_8.ppc64le.rpm webkit2gtk3-jsc-devel-debuginfo-0:2.52.5-1.el9_8.ppc64le.rpm