Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:25918: Important: webkit2gtk3 security update

This Red Hat security advisory addresses multiple vulnerabilities in the webkit2gtk3 package for RHEL 8, rated Important, where processing malicious web content can cause unexpected process crashes or bypass Content Security Policy. The article lists numerous CVEs but does not provide specific CVSS scores or version ranges for the affected Linux package. Red Hat has released an update; administrators should apply the patch via the referenced Red Hat article.
Read Full Article →

Red Hat Product Errata RHSA-2026:25918 - Security Advisory Issued: 2026-06-15 Updated: 2026-06-15 RHSA-2026:25918 - Security Advisory Overview Updated Packages Synopsis Important: webkit2gtk3 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28946) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28847) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28883) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28901) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28902) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28903) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28904) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28905) webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-28907) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28942) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28947) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28953) webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28955) webkitgtk: An app may be able to access sensitive user data (CVE-2026-28958) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43658) webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-43660) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2471790 - CVE-2026-28946 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2483955 - CVE-2026-28847 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483956 - CVE-2026-28883 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483957 - CVE-2026-28901 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483958 - CVE-2026-28902 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483959 - CVE-2026-28903 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483960 - CVE-2026-28904 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483961 - CVE-2026-28905 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483962 - CVE-2026-28907 webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced BZ - 2483963 - CVE-2026-28942 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2483964 - CVE-2026-28947 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2483965 - CVE-2026-28953 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483966 - CVE-2026-28955 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash BZ - 2483967 - CVE-2026-28958 webkitgtk: An app may be able to access sensitive user data BZ - 2483968 - CVE-2026-43658 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash BZ - 2483969 - CVE-2026-43660 webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced CVEs CVE-2026-28847 CVE-2026-28883 CVE-2026-28901 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-43658 CVE-2026-43660 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM webkit2gtk3-2.52.4-1.el8_10.src.rpm SHA-256: 13923fcdd77ca9ab4c588a5ac4abce4558c674c1a50bf82f7e6f6a9e20d64c42 x86_64 webkit2gtk3-2.52.4-1.el8_10.i686.rpm SHA-256: f15ee7ac4ea2424c9d4fcb41f53b21ebf7f53da5770e11471199d1c86fbc0e71 webkit2gtk3-2.52.4-1.el8_10.x86_64.rpm SHA-256: e94809ffd3785f1fc9e682829e9d94222404f212194fa55c3cadafb32cbd8aa6 webkit2gtk3-debuginfo-2.52.4-1.el8_10.i686.rpm SHA-256: ef69085d675dca891341e65d3d3eb2b247b1069d3fe5528c33ef05b755c5ecbf webkit2gtk3-debuginfo-2.52.4-1.el8_10.x86_64.rpm SHA-256: b3f8cbd38699ce9e50c4a2a4aa8247dc6c41e65d1fa18abfc342272ea0c2984b webkit2gtk3-debugsource-2.52.4-1.el8_10.i686.rpm SHA-256: a8a987acbd30cbc47c8807fa3cb950424fd98eae4d77afdec0e11fdf606733e6 webkit2gtk3-debugsource-2.52.4-1.el8_10.x86_64.rpm SHA-256: 09dbb09b2bb7cdc308e9e68e678808b1d08b3132eb4b0176e945bb11d5f1c4ce webkit2gtk3-devel-2.52.4-1.el8_10.i686.rpm SHA-256: fd12aa79e48f62f48981b3464a463c017f50ab8f66b377e6e9b8926dd364ef43 webkit2gtk3-devel-2.52.4-1.el8_10.x86_64.rpm SHA-256: 44c5fc4e623e27dfb775bc65fec9f3321772dde023daf4961d79be8c556f4315 webkit2gtk3-devel-debuginfo-2.52.4-1.el8_10.i686.rpm SHA-256: 308b73e79b3d83bc04c65cc9ac3392329e6d292f074daaab4be55acaed7defa6 webkit2gtk3-devel-debuginfo-2.52.4-1.el8_10.x86_64.rpm SHA-256: f51360b9b0b00bdb1fa572afeb040f3d80eb9af5fa85eba701a1b32c1559c0c5 webkit2gtk3-jsc-2.52.4-1.el8_10.i686.rpm SHA-256: 9379af32c495de15d66b702e496936c2194e935bf8f3ee6705efcd0541266ba4 webkit2gtk3-jsc-2.52.4-1.el8_10.x86_64.rpm SHA-256: d8ef19e5fdbfe71285b4acab40fcc72105cb33907a665eefa59b2191bcfd571a webkit2gtk3-jsc-debuginfo-2.52.4-1.el8_10.i686.rpm SHA-256: a0a18ffed1060232ee2f3a0146fac2165cb31178c780ae9af50257e2a49fac66 webkit2gtk3-jsc-debuginfo-2.52.4-1.el8_10.x86_64.rpm SHA-256: b216252620c744204f7ed78f441fc90d5c553d641c5e895a788f36da508e813b webkit2gtk3-jsc-devel-2.52.4-1.el8_10.i686.rpm SHA-256: af8ff38002b6a3f57c65498258e8fa7b2fda59370ed279300154d42a58245bc8 webkit2gtk3-jsc-devel-2.52.4-1.el8_10.x86_64.rpm SHA-256: 67a2dff9055c69f71183e16ecba169229a17142730e6d31ed8949559e40e8059 webkit2gtk3-jsc-devel-debuginfo-2.52.4-1.el8_10.i686.rpm SHA-256: 7b5a6d42e0ce35a3285cff1e4b492349a4db583672dfb88d31fe9837d22f2dc2 webkit2gtk3-jsc-devel-debuginfo-2.52.4-1.el8_10.x86_64.rpm SHA-256: 18314833ed769c0ec4b36a60a0890367109c60842c2b5a7b6e9b6e4d6ab622a5 Red Hat Enterprise Linux for IBM z Systems 8 SRPM webkit2gtk3-2.52.4-1.el8_10.src.rpm SHA-256: 13923fcdd77ca9ab4c588a5ac4abce4558c674c1a50bf82f7e6f6a9e20d64c42 s390x webkit2gtk3-2.52.4-1.el8_10.s390x.rpm SHA-256: 4532bd87bde18acaafbab5932c608fe284a008411dae771fe83d7cf24b441598 webkit2gtk3-debuginfo-2.52.4-1.el8_10.s390x.rpm SHA-256: 5cc1df98e27a78859369dffbb120e23bf98c23736f3fd564212f94d9905f8c42 webkit2gtk3-debugsource-2.52.4-1.el8_10.s390x.rpm SHA-256: e16fc61d19bbd76598c45962dcd89f93d2af13bbecf6e6a1a6d72cac3889f5dc webkit2gtk3-devel-2.52.4-1.el8_10.s390x.rpm SHA-256: de49d23c7141d6bdfb6b20a5606fc2e9e9497b7a066a9e2daa40ead88081d00c webkit2gtk3-devel-debuginfo-2.52.4-1.el8_10.s390x.rpm SHA-256: a934eb15aee2a510827031cc524c8c24ce3c0dbfcb0bfbcc1a9abdd842a6456d webkit2gtk3-jsc-2.52.4-1.el8_10.s390x.rpm SHA-256: d280882ad0a7a573ecff8b71db640c7696bc19045c1e7e8f9b27a2a74ac0e9fc webkit2gtk3-jsc-debuginfo-2.52.4-1.el8_10.s390x.rpm SHA-256: da71f8972f7803db09886e1d0c01f02901ea764809c1e23a0cc6cca2ec35549a webkit2gtk3-jsc-devel-2.52.4-1.el8_10.s390x.rpm SHA-256: 9939832e433671ce3fca9923cdffef73dbe7b16cacc2bb42c8bbc20201bf77d5 webkit2gtk3-jsc-devel-debuginfo-2.52.4-1.el8_10.s390x.rpm SHA-256: ca569a1e617dc8ba4dfa744377fca366c9345b6cad56fc9d8bed98c34a34838d Red Hat Enterprise Linux for Power, little endian 8 SRPM webkit2gtk3-2.52.4-1.el8_10.src.rpm SHA-256: 13923fcdd77ca9ab4c588a5ac4abce4558c674c1a50bf82f7e6f6a9e20d64c42 ppc64le webkit2gtk3-2.52.4-1.el8_10.ppc64le.rpm SHA-256: 1644d4c61e5450a9557b5012df5c7b98ca6d5f342c23d3ab3cb95604d3f21a5a webkit2gtk3-debuginfo-2.52.4-1.el8_10.ppc64le.rpm SHA-256: 0e1f853adcaf032b909ae7be2dbf7787df37cff37a62f95413cec2e8b86c17b2 webkit2gtk3-debugsource-2.52.4-1.el8_10.ppc64le.rpm SHA-256: 3124adef12f7fbae166

Share this article