Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
红帽产品勘误 RHSA-2026:16056 - Security Advisory
发布:
2026-05-11
已更新:
2026-05-11

RHSA-2026:16056 - Security Advisory

  • 概述
  • 更新的软件包

概述

Important: webkit2gtk3 security update

类型/严重性

Security Advisory: Important

Red Hat Insights 补丁分析

识别并修复受此公告影响的系统。

查看受影响的系统

标题

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

描述

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43213)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43214)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43457)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43511)
  • webkitgtk: Processing maliciously crafted web content may disclose internal states of the app (CVE-2025-46299)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20608)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20635)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20636)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20644)
  • webkitgtk: A remote attacker may be able to cause a denial-of-service (CVE-2026-20652)
  • webkitgtk: A website may be able to track users through Safari web extensions (CVE-2026-20676)
  • webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy (CVE-2026-20643)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20664)
  • webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-20665)
  • webkitgtk: A maliciously crafted webpage may be able to fingerprint the user (CVE-2026-20691)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28857)
  • webkitgtk: A malicious website may be able to process restricted web content outside the sandbox (CVE-2026-28859)
  • webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack (CVE-2026-28871)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

解决方案

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

受影响的产品

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

修复

  • BZ - 2448781 - CVE-2025-43213 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
  • BZ - 2448782 - CVE-2025-43214 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
  • BZ - 2448786 - CVE-2025-43457 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
  • BZ - 2448787 - CVE-2025-43511 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2448788 - CVE-2025-46299 webkitgtk: Processing maliciously crafted web content may disclose internal states of the app
  • BZ - 2448789 - CVE-2026-20608 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2448790 - CVE-2026-20635 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2448791 - CVE-2026-20636 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2448792 - CVE-2026-20644 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2448793 - CVE-2026-20652 webkitgtk: A remote attacker may be able to cause a denial-of-service
  • BZ - 2448794 - CVE-2026-20676 webkitgtk: A website may be able to track users through Safari web extensions
  • BZ - 2453000 - CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy
  • BZ - 2453001 - CVE-2026-20664 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2453002 - CVE-2026-20665 webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced
  • BZ - 2453003 - CVE-2026-20691 webkitgtk: A maliciously crafted webpage may be able to fingerprint the user
  • BZ - 2453004 - CVE-2026-28857 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2453006 - CVE-2026-28859 webkitgtk: A malicious website may be able to process restricted web content outside the sandbox
  • BZ - 2453008 - CVE-2026-28871 webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack

CVE

  • CVE-2025-43213
  • CVE-2025-43214
  • CVE-2025-43457
  • CVE-2025-43511
  • CVE-2025-46299
  • CVE-2026-20608
  • CVE-2026-20635
  • CVE-2026-20636
  • CVE-2026-20643
  • CVE-2026-20644
  • CVE-2026-20652
  • CVE-2026-20664
  • CVE-2026-20665
  • CVE-2026-20676
  • CVE-2026-20691
  • CVE-2026-28857
  • CVE-2026-28859
  • CVE-2026-28871

参考

  • https://access.redhat.com/security/updates/classification/#important
备注: 可能有这些软件包的更新版本。 点击软件包名称查看详情。

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4

SRPM
webkit2gtk3-2.52.3-1.el8_4.src.rpm SHA-256: 7a473aba4295fba69f4174d0464e03477cd8438bd631e55bfb08b4da332f680f
x86_64
webkit2gtk3-2.52.3-1.el8_4.i686.rpm SHA-256: a57e4ef2f240c1950dbd7840730b67b6a4474d83a440b901303855b2f435f834
webkit2gtk3-2.52.3-1.el8_4.x86_64.rpm SHA-256: 820a2456890f0420bf6d1c17af364bf394cf66c46adbd169c4c61f2ba5021089
webkit2gtk3-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 9c5e212a75e1820e275ac63965fbe16f6bbc61d75e6a1dec94a401c46439246f
webkit2gtk3-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 2d38a3f4b9e91bd2230ac25becfb6f24812c9438adefd85ce4c3b064843265d4
webkit2gtk3-debugsource-2.52.3-1.el8_4.i686.rpm SHA-256: a66280a1370250a0ad00f8e700509c151b21f9e35c333ed09a2639d14bea1dcb
webkit2gtk3-debugsource-2.52.3-1.el8_4.x86_64.rpm SHA-256: 87a3f2a4bf327682fac8d1e4bb53f755ac9f1d7c7690a9191349b9f2f07efff3
webkit2gtk3-devel-2.52.3-1.el8_4.i686.rpm SHA-256: 4584e6e446d43681557c4bdac5c56aa920df4f3846d196726bf71094a3ab7b82
webkit2gtk3-devel-2.52.3-1.el8_4.x86_64.rpm SHA-256: 1f46291724f37dc8a0e81cb493bd162fd869802adf24d2135f7962c94c7edb41
webkit2gtk3-devel-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 44db2f29f2ace067976db8b211aeba59ba666f1b08d7c38bfbcc2937e8c198a5
webkit2gtk3-devel-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 5579a14e6a85677c7ba24a35fde53e26e7ff60b6133d2ec6a9b667799359a349
webkit2gtk3-jsc-2.52.3-1.el8_4.i686.rpm SHA-256: ca69f9e76386a605199def3ba14a50add67427948517a99aa57d8331a07eed83
webkit2gtk3-jsc-2.52.3-1.el8_4.x86_64.rpm SHA-256: 0422f70339f3761d7fbc97d3840dd689ce5923967572c8e2c2a8cd5d642256d5
webkit2gtk3-jsc-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 8db1591fa122fccb4defac0753fa85a2ac07c32cceb21ddff7268efaca14a5e1
webkit2gtk3-jsc-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 052ea20145a3ca4d2f28c5526f0798b38cb18da7b32cfc057324beb663e0972c
webkit2gtk3-jsc-devel-2.52.3-1.el8_4.i686.rpm SHA-256: 83d7e47b4feef649d55c8832139b47e2dca9c3d876ebce41a0539b38a1ff7d53
webkit2gtk3-jsc-devel-2.52.3-1.el8_4.x86_64.rpm SHA-256: 3aa5883907f2c6b3ed4336b42978d8b3790ead027eab1e793b5a729e3a615376
webkit2gtk3-jsc-devel-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 0f80dbf0f261749569c9772e4416b0f6074eba42cd67442d6a8c816c42e4323c
webkit2gtk3-jsc-devel-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 2a53191b3dc9d33263ac4feca07eb407ccb772938a131531b8a16ff00f0db86b

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
webkit2gtk3-2.52.3-1.el8_4.src.rpm SHA-256: 7a473aba4295fba69f4174d0464e03477cd8438bd631e55bfb08b4da332f680f
x86_64
webkit2gtk3-2.52.3-1.el8_4.i686.rpm SHA-256: a57e4ef2f240c1950dbd7840730b67b6a4474d83a440b901303855b2f435f834
webkit2gtk3-2.52.3-1.el8_4.x86_64.rpm SHA-256: 820a2456890f0420bf6d1c17af364bf394cf66c46adbd169c4c61f2ba5021089
webkit2gtk3-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 9c5e212a75e1820e275ac63965fbe16f6bbc61d75e6a1dec94a401c46439246f
webkit2gtk3-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 2d38a3f4b9e91bd2230ac25becfb6f24812c9438adefd85ce4c3b064843265d4
webkit2gtk3-debugsource-2.52.3-1.el8_4.i686.rpm SHA-256: a66280a1370250a0ad00f8e700509c151b21f9e35c333ed09a2639d14bea1dcb
webkit2gtk3-debugsource-2.52.3-1.el8_4.x86_64.rpm SHA-256: 87a3f2a4bf327682fac8d1e4bb53f755ac9f1d7c7690a9191349b9f2f07efff3
webkit2gtk3-devel-2.52.3-1.el8_4.i686.rpm SHA-256: 4584e6e446d43681557c4bdac5c56aa920df4f3846d196726bf71094a3ab7b82
webkit2gtk3-devel-2.52.3-1.el8_4.x86_64.rpm SHA-256: 1f46291724f37dc8a0e81cb493bd162fd869802adf24d2135f7962c94c7edb41
webkit2gtk3-devel-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 44db2f29f2ace067976db8b211aeba59ba666f1b08d7c38bfbcc2937e8c198a5
webkit2gtk3-devel-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 5579a14e6a85677c7ba24a35fde53e26e7ff60b6133d2ec6a9b667799359a349
webkit2gtk3-jsc-2.52.3-1.el8_4.i686.rpm SHA-256: ca69f9e76386a605199def3ba14a50add67427948517a99aa57d8331a07eed83
webkit2gtk3-jsc-2.52.3-1.el8_4.x86_64.rpm SHA-256: 0422f70339f3761d7fbc97d3840dd689ce5923967572c8e2c2a8cd5d642256d5
webkit2gtk3-jsc-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 8db1591fa122fccb4defac0753fa85a2ac07c32cceb21ddff7268efaca14a5e1
webkit2gtk3-jsc-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 052ea20145a3ca4d2f28c5526f0798b38cb18da7b32cfc057324beb663e0972c
webkit2gtk3-jsc-devel-2.52.3-1.el8_4.i686.rpm SHA-256: 83d7e47b4feef649d55c8832139b47e2dca9c3d876ebce41a0539b38a1ff7d53
webkit2gtk3-jsc-devel-2.52.3-1.el8_4.x86_64.rpm SHA-256: 3aa5883907f2c6b3ed4336b42978d8b3790ead027eab1e793b5a729e3a615376
webkit2gtk3-jsc-devel-debuginfo-2.52.3-1.el8_4.i686.rpm SHA-256: 0f80dbf0f261749569c9772e4416b0f6074eba42cd67442d6a8c816c42e4323c
webkit2gtk3-jsc-devel-debuginfo-2.52.3-1.el8_4.x86_64.rpm SHA-256: 2a53191b3dc9d33263ac4feca07eb407ccb772938a131531b8a16ff00f0db86b

Red Hat 安全团队联络方式为 secalert@redhat.com。 更多联络细节请参考 https://access.redhat.com/security/team/contact/。

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility