{"id":"MGASA-2026-0064","summary":"Updated webkit2 packages fix security vulnerabilities","details":"CVE-2025-43457 Processing maliciously crafted web content may lead to an\nunexpected Safari crash. A use-after-free issue was addressed with improved\nmemory management.\nCVE-2026-20608 Processing maliciously crafted web content may lead to an\nunexpected process crash. This issue was addressed through improved state\nmanagement.\nCVE-2026-20635 Processing maliciously crafted web content may lead to an\nunexpected process crash. The issue was addressed with improved memory\nhandling.\nCVE-2026-20636 Processing maliciously crafted web content may lead to an\nunexpected process crash. The issue was addressed with improved memory\nhandling.\nCVE-2026-20644 Processing maliciously crafted web content may lead to an\nunexpected process crash. The issue was addressed with improved memory\nhandling.\nCVE-2026-20652 A remote attacker may be able to cause a denial-of-service.\nThe issue was addressed with improved memory handling.\nCVE-2026-20676 A website may be able to track users through Safari web\nextensions. This issue was addressed through improved state management.\n","modified":"2026-04-16T04:41:24.981781474Z","published":"2026-03-24T17:53:34Z","upstream":["CVE-2025-43457","CVE-2026-20608","CVE-2026-20635","CVE-2026-20636","CVE-2026-20644","CVE-2026-20652","CVE-2026-20676"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0064.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35228"},{"type":"WEB","url":"https://webkitgtk.org/2026/03/12/webkitgtk2.50.6-released.html"},{"type":"WEB","url":"https://webkitgtk.org/security/WSA-2026-0001.html"}],"affected":[{"package":{"name":"webkit2","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/webkit2?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.50.6-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0064.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}