Important: webkit2gtk3 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:9692", "synopsis": "Important: webkit2gtk3 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for webkit2gtk3.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.\n\nSecurity Fix(es):\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43213)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43214)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43457)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43511)\n\n* webkitgtk: Processing maliciously crafted web content may disclose internal states of the app (CVE-2025-46299)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20608)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20635)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20636)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20644)\n\n* webkitgtk: A remote attacker may be able to cause a denial-of-service (CVE-2026-20652)\n\n* webkitgtk: A website may be able to track users through Safari web extensions (CVE-2026-20676)\n\n* webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy (CVE-2026-20643)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-20664)\n\n* webkitgtk: Processingmaliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2026-20665)\n\n* webkitgtk: A maliciously crafted webpage may be able to fingerprint the user (CVE-2026-20691)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-28857)\n\n* webkitgtk: A malicious website may be able to process restricted web content outside the sandbox (CVE-2026-28859)\n\n* webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack (CVE-2026-28871)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2448781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448781", "description": ""}, {"ticket": "2448782", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448782", "description": ""}, {"ticket": "2448786", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448786", "description": ""}, {"ticket": "2448787", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448787", "description": ""}, {"ticket": "2448788", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448788", "description": ""}, {"ticket": "2448789", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448789", "description": ""}, {"ticket": "2448790", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448790", "description": ""}, {"ticket": "2448791", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448791", "description": ""}, {"ticket": "2448792", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448792", "description": ""}, {"ticket": "2448793","sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448793", "description": ""}, {"ticket": "2448794", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448794", "description": ""}, {"ticket": "2453000", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453000", "description": ""}, {"ticket": "2453001", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453001", "description": ""}, {"ticket": "2453002", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453002", "description": ""}, {"ticket": "2453003", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453003", "description": ""}, {"ticket": "2453004", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453004", "description": ""}, {"ticket": "2453006", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453006", "description": ""}, {"ticket": "2453008", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453008", "description": ""}], "cves": [{"name": "CVE-2025-43213", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-43213", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2025-43214", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-43214", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2025-43457", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-43457", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-416"}, {"name": "CVE-2025-43511", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-43511","cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-416"}, {"name": "CVE-2025-46299", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-46299", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "cvss3BaseScore": "6.5", "cwe": "CWE-909"}, {"name": "CVE-2026-20608", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20608", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-20635", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20635", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-20636", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20636", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-20643", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20643", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N", "cvss3BaseScore": "5.4", "cwe": "CWE-346"}, {"name": "CVE-2026-20644", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20644", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-20652", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20652", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-120"}, {"name": "CVE-2026-20664", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20664", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"},{"name": "CVE-2026-20665", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20665", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L", "cvss3BaseScore": "5.4", "cwe": "CWE-693"}, {"name": "CVE-2026-20676", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20676", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "cvss3BaseScore": "4.3", "cwe": "CWE-201"}, {"name": "CVE-2026-20691", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-20691", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "cvss3BaseScore": "4.3", "cwe": "CWE-497"}, {"name": "CVE-2026-28857", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28857", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-28859", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28859", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2026-28871", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28871", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "cvss3BaseScore": "4.3", "cwe": "CWE-79"}], "references": [], "publishedAt": "2026-04-24T12:03:31.152911Z", "rpms": {"Rocky Linux 9": {"nvras": ["webkit2gtk3-0:2.52.3-0.el9_7.1.src.rpm", "webkit2gtk3-0:2.52.3-0.el9_7.1.x86_64.rpm", "webkit2gtk3-debuginfo-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-debuginfo-0:2.52.3-0.el9_7.1.i686.rpm", "webkit2gtk3-debuginfo-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-debuginfo-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-debuginfo-0:2.52.3-0.el9_7.1.x86_64.rpm", "webkit2gtk3-debugsource-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-debugsource-0:2.52.3-0.el9_7.1.i686.rpm","webkit2gtk3-debugsource-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-debugsource-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-debugsource-0:2.52.3-0.el9_7.1.x86_64.rpm", "webkit2gtk3-devel-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-devel-0:2.52.3-0.el9_7.1.i686.rpm", "webkit2gtk3-devel-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-devel-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-devel-0:2.52.3-0.el9_7.1.x86_64.rpm", "webkit2gtk3-devel-debuginfo-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-devel-debuginfo-0:2.52.3-0.el9_7.1.i686.rpm", "webkit2gtk3-devel-debuginfo-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-devel-debuginfo-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-devel-debuginfo-0:2.52.3-0.el9_7.1.x86_64.rpm", "webkit2gtk3-jsc-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-jsc-0:2.52.3-0.el9_7.1.i686.rpm", "webkit2gtk3-jsc-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-jsc-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-jsc-0:2.52.3-0.el9_7.1.x86_64.rpm", "webkit2gtk3-jsc-debuginfo-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-jsc-debuginfo-0:2.52.3-0.el9_7.1.i686.rpm", "webkit2gtk3-jsc-debuginfo-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-jsc-debuginfo-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-0:2.52.3-0.el9_7.1.i686.rpm", "webkit2gtk3-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-jsc-debuginfo-0:2.52.3-0.el9_7.1.x86_64.rpm", "webkit2gtk3-jsc-devel-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-jsc-devel-0:2.52.3-0.el9_7.1.i686.rpm", "webkit2gtk3-jsc-devel-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-jsc-devel-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-jsc-devel-0:2.52.3-0.el9_7.1.x86_64.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.52.3-0.el9_7.1.aarch64.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.52.3-0.el9_7.1.i686.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.52.3-0.el9_7.1.ppc64le.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.52.3-0.el9_7.1.s390x.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.52.3-0.el9_7.1.x86_64.rpm"]}},"rebootSuggested": false, "buildReferences": []}. Security advisory detailing important updates for webkit2gtk3 on Rocky Linux 9 to mitigate potential impacts.. Rocky Linux security, webkit2gtk3 update, denial of service fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for wpa_supplicant ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0404-1 Rating: important References: #1182805 Cross-References: CVE-2021-27803 CVSS scores: CVE-2021-27803 (NVD) : 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-27803 (SUSE): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for wpa_supplicant fixes the following issues: - CVE-2021-27803: Fixed a P2P provision discovery processing vulnerability (bsc#1182805). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-404=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): wpa_supplicant-2.9-lp152.8.9.1 wpa_supplicant-debuginfo-2.9-lp152.8.9.1 wpa_supplicant-debugsource-2.9-lp152.8.9.1 wpa_supplicant-gui-2.9-lp152.8.9.1 wpa_supplicant-gui-debuginfo-2.9-lp152.8.9.1 References: https://www.suse.com/security/cve/CVE-2021-27803.html https://bugzilla.suse.com/1182805 . Critical openSUSE patch released for wpa_supplicant targeting CVE-2021-27803. Suggested installation steps provided.. openSUSE Security Update,wpa_supplicant fixes,network security patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.