Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 477
Alerts This Week
Warning Icon 1 477

Debian webkit2gtk Critical JavaScript Exec Risk DSA-6398-1

debian
Calendar Grey July 23, 2026
Scroller Debian
Uncover critical vulnerabilities in WebKitGTK affecting Debian, including JavaScript execution risks and more.
Multiple vulnerabilities in WebKitGTK have been identified, leading to process crashes, memory corruption, and potential data leaks; users are urged to upgrade to the latest versio...

Summary

CVE-2024-4367

Thomas Rinsma discovered that a type check was missing when
handling fonts in PDF.js, which would allow arbitrary JavaScript
execution in the PDF.js context.

CVE-2026-28847

DARKNAVY, an anonymous researcher and Daniel Rhea discovered that
processing maliciously crafted web content may lead to an
unexpected process crash.

CVE-2026-28883

Kwak Kiyong discovered that processing maliciously crafted web
content may lead to an unexpected process crash.

CVE-2026-28901

Joshua Rogers, Luigino Camastra, Igor Morgenstern, Guido Vranken,
Maher Azzouzi and Ngan Nguyen discovered that processing
maliciously crafted web content may lead to an unexpected process
crash.

CVE-2026-28902

Tristan Madani and Nathaniel Oh discovered that processing
maliciously crafted web content may lead to an unexpected process
crash.

CVE-2026-28903

Mateusz Krzywicki discovered that processing maliciously crafted
web content may lead to an unexpected process crash.

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
CVE ID: CVE-2024-4367 CVE-2026-28847 CVE-2026-28883 CVE-2026-28901

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.