{"id":"RLSA-2026:42088","summary":"Important: webkit2gtk3 security update","details":"WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.\n\nSecurity Fix(es):\n\n* Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699)\n\n* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712)\n\n* webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720)\n\n* webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721)\n\n* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742)\n\n* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-07-21T06:30:06.942614604Z","published":"2026-07-21T06:00:53.836342Z","upstream":["CVE-2024-4367","CVE-2026-39872","CVE-2026-43663","CVE-2026-43676","CVE-2026-43699","CVE-2026-43701","CVE-2026-43705","CVE-2026-43707","CVE-2026-43712","CVE-2026-43713","CVE-2026-43715","CVE-2026-43716","CVE-2026-43720","CVE-2026-43721","CVE-2026-43725","CVE-2026-43726","CVE-2026-43727","CVE-2026-43731","CVE-2026-43732","CVE-2026-43734","CVE-2026-43740","CVE-2026-43742","CVE-2026-43745"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2026:42088"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2280382"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500519"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500520"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500521"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500522"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500523"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500524"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500525"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500526"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500527"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500528"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500529"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500530"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500531"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500532"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500533"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500534"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500535"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500536"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500537"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500538"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500539"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500540"}],"affected":[{"package":{"name":"webkit2gtk3","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/webkit2gtk3?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:2.52.5-1.el8_10"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2026:42088.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}