webkit2gtk3-2.52.4-1.el9_8

エラータID: AXSA:2026-1338:05

Release date: 
Friday, July 24, 2026 - 02:32
Subject: 
webkit2gtk3-2.52.4-1.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28946)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28847)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28883)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28901)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28902)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28903)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28904)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28905)
* webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-28907)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28942)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28947)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28953)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28955)
* webkitgtk: An app may be able to access sensitive user data (CVE-2026-28958)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43658)
* webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-43660)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-28847
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28883
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28901
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28902
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28903
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28904
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28905
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28907
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
CVE-2026-28942
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
CVE-2026-28946
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
CVE-2026-28947
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
CVE-2026-28953
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28955
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2026-28958
This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app may be able to access sensitive user data.
CVE-2026-43658
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected Safari crash.
CVE-2026-43660
A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. webkit2gtk3-2.52.4-1.el9_8.src.rpm
    MD5: 37a89124ff1bad7f7a66778903b86185
    SHA-256: 7795afd9c48e4b833eeba45cf6cba284083ef9ca47356028d0e9ee83159e0ce5
    Size: 62.15 MB

Asianux Server 9 for x86_64
  1. webkit2gtk3-2.52.4-1.el9_8.i686.rpm
    MD5: 273eb1e1d0435a19f1187ea5b731f70b
    SHA-256: 133efffbdbb021812f7adcd52662030c5162a004368cd74e380a2b4c913eb3fb
    Size: 27.91 MB
  2. webkit2gtk3-2.52.4-1.el9_8.x86_64.rpm
    MD5: afc84391662f8142590a39c5dc99231e
    SHA-256: f5c75d1d6da0265e89eadcc9127ff462ae1d8cf363918e0defd80bee49342f03
    Size: 28.64 MB
  3. webkit2gtk3-devel-2.52.4-1.el9_8.i686.rpm
    MD5: b578dc9914194f2f8fe5b99e2ac79915
    SHA-256: ce03a93df1d50bc6df77881a79b79db332355224b8e6f05f6ea0cd592d3adf4a
    Size: 372.23 kB
  4. webkit2gtk3-devel-2.52.4-1.el9_8.x86_64.rpm
    MD5: a5b5778291d1b178cddfeb7e0a1b88c4
    SHA-256: 68699998cfd1f4edc68795aa4dad974ff5e971d4e68d66c1da96cd368a1ee880
    Size: 370.95 kB
  5. webkit2gtk3-jsc-2.52.4-1.el9_8.i686.rpm
    MD5: 2afa05d91c6528467fc0550c3041a406
    SHA-256: e321e67a27d8b47312aa8511c72d28376ffa7e1c468b2e684570b09dc15fc859
    Size: 4.15 MB
  6. webkit2gtk3-jsc-2.52.4-1.el9_8.x86_64.rpm
    MD5: 0cbd29c61dd494b12f99e0e281631f48
    SHA-256: 5a63d85e563306b7ff01a2b343e64a9587760d21c2ca69a2916185fd1aea0113
    Size: 8.88 MB
  7. webkit2gtk3-jsc-devel-2.52.4-1.el9_8.i686.rpm
    MD5: 72d00f49cd3be3dded15aff298d8e69d
    SHA-256: e5524326e1f9431254c397eb6a830f49d4d5d6b429b8bfe05e899a754a28abb8
    Size: 171.31 kB
  8. webkit2gtk3-jsc-devel-2.52.4-1.el9_8.x86_64.rpm
    MD5: a6eb95b8494bd22f034cdc7aeef23375
    SHA-256: 05afd699ae4959409c14aca6e92f639c13fb448becaabb47a7a41b4fda1e756c
    Size: 163.03 kB