ALSA-2026:25927

See a problem?
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:25927.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2026:25927
Related
  • CVE-2026-28847
  • CVE-2026-28883
  • CVE-2026-28901
  • CVE-2026-28902
  • CVE-2026-28903
  • CVE-2026-28904
  • CVE-2026-28905
  • CVE-2026-28907
  • CVE-2026-28942
  • CVE-2026-28946
  • CVE-2026-28947
  • CVE-2026-28953
  • CVE-2026-28955
  • CVE-2026-28958
  • CVE-2026-43658
  • CVE-2026-43660
Published
2026-06-15T00:00:00Z
Modified
2026-06-16T09:14:22.089552447Z
Summary
Important: webkit2gtk3 security update
Details

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28946)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28847)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28883)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28901)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28902)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28903)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28904)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28905)
  • webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-28907)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28942)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28947)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28953)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28955)
  • webkitgtk: An app may be able to access sensitive user data (CVE-2026-28958)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43658)
  • webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-43660)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:9 / webkit2gtk3

Package

Name
webkit2gtk3
Purl
pkg:rpm/almalinux/webkit2gtk3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.52.4-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:25927.json"

AlmaLinux:9 / webkit2gtk3-devel

Package

Name
webkit2gtk3-devel
Purl
pkg:rpm/almalinux/webkit2gtk3-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.52.4-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:25927.json"

AlmaLinux:9 / webkit2gtk3-jsc

Package

Name
webkit2gtk3-jsc
Purl
pkg:rpm/almalinux/webkit2gtk3-jsc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.52.4-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:25927.json"

AlmaLinux:9 / webkit2gtk3-jsc-devel

Package

Name
webkit2gtk3-jsc-devel
Purl
pkg:rpm/almalinux/webkit2gtk3-jsc-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.52.4-1.el9_8

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:25927.json"