[Security Advisory] ALSA-2026:69098: webkit2gtk3 security update (Important)
Hi, You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux. AlmaLinux: 9 Type: Security Severity: Important Release date: 2026-09-30 Summary: WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154) * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173) * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161) * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176) * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984) * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804) * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713) * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787) * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783) * webkitgtk: use-after-free of JSCValue function parameters (CVE-2026-78376) * chromium-browser: Skia: Information disclosure via out-of-bounds read in crafted media file (CVE-2026-79020) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43795) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-64715) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64718) * webkitgtk: Visiting a maliciously crafted website may leak sensitive data (CVE-2026-64778) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64779) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64780) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64782) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64784) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65331) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65332) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65334) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65335) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65336) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65337) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65338) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65340) * webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2026-65341) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65351) * webkitgtk: Validate the full FeatureList array once in OpenTypeVerticalData findFeature (CVE-2026-83596) * chromium-browser: skia: chromium-browser: Information leak in Skia (CVE-2026-84359) * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-84635) * webkitgtk: Processing maliciously crafted web content may disclose sensitive user information (CVE-2026-64753) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-69098.html This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/. Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org. Kind regards, AlmaLinux Team
participants (1)
-
AlmaLinux Errata Notifications