Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-2034 http://linux.oracle.com/errata/ELSA-2025-2034.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: webkit2gtk3-2.46.6-1.el8_10.i686.rpm webkit2gtk3-2.46.6-1.el8_10.x86_64.rpm webkit2gtk3-devel-2.46.6-1.el8_10.i686.rpm webkit2gtk3-devel-2.46.6-1.el8_10.x86_64.rpm webkit2gtk3-jsc-2.46.6-1.el8_10.i686.rpm webkit2gtk3-jsc-2.46.6-1.el8_10.x86_64.rpm webkit2gtk3-jsc-devel-2.46.6-1.el8_10.i686.rpm webkit2gtk3-jsc-devel-2.46.6-1.el8_10.x86_64.rpm aarch64: webkit2gtk3-2.46.6-1.el8_10.aarch64.rpm webkit2gtk3-devel-2.46.6-1.el8_10.aarch64.rpm webkit2gtk3-jsc-2.46.6-1.el8_10.aarch64.rpm webkit2gtk3-jsc-devel-2.46.6-1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//webkit2gtk3-2.46.6-1.el8_10.src.rpm Related CVEs: CVE-2024-54543 CVE-2025-24143 CVE-2025-24150 CVE-2025-24158 CVE-2025-24162 Description of changes: [2.46.6-1] - Update to 2.46.6 _______________________________________________ El-errata mailing list
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-54479 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4009-1
Important: webkit2gtk3 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1919", "synopsis": "Important: webkit2gtk3 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for webkit2gtk3.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.\n\nSecurity Fix(es):\n\n* WebKitGTK: use-after-free leads to arbitrary code execution (CVE-2023-28205)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2185724", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2185724", "description": ""}], "cves": [{"name": "CVE-2023-28205", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28205", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-04-26T15:28:43.734178Z", "rpms": {"Rocky Linux 8": {"nvras": ["webkit2gtk3-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-0:2.36.7-1.el8_7.3.src.rpm", "webkit2gtk3-debuginfo-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-debugsource-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-devel-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-devel-debuginfo-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-jsc-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-jsc-debuginfo-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-jsc-devel-0:2.36.7-1.el8_7.3.aarch64.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.36.7-1.el8_7.3.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important webkit2gtk3 enhancement for Rocky Linux 8 addresses vulnerabilities and theirconsequences. Ensure your safety!. web security update, webkit2gtk3 patch, critical fix. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-6540 https://linux.oracle.com/errata/ELSA-2022-6540.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: webkit2gtk3-2.36.7-1.el8_6.i686.rpm webkit2gtk3-2.36.7-1.el8_6.x86_64.rpm webkit2gtk3-devel-2.36.7-1.el8_6.i686.rpm webkit2gtk3-devel-2.36.7-1.el8_6.x86_64.rpm webkit2gtk3-jsc-2.36.7-1.el8_6.i686.rpm webkit2gtk3-jsc-2.36.7-1.el8_6.x86_64.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_6.i686.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_6.x86_64.rpm aarch64: webkit2gtk3-2.36.7-1.el8_6.aarch64.rpm webkit2gtk3-devel-2.36.7-1.el8_6.aarch64.rpm webkit2gtk3-jsc-2.36.7-1.el8_6.aarch64.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_6.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/webkit2gtk3-2.36.7-1.el8_6.src.rpm Related CVEs: CVE-2022-32893 Description of changes: [2.36.7-1] - Update to 2.36.7 Related: #2123429 _______________________________________________ El-errata mailing list
The webkit2 package has been updated to version 2.36.4, fixing several security issues and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=30608 . MGASA-2022-0254 - Updated webkit2 packages fix security vulnerability Publication date: 12 Jul 2022 URL: https://advisories.mageia.org/MGASA-2022-0254.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-22662, CVE-2022-22677, CVE-2022-26710 The webkit2 package has been updated to version 2.36.4, fixing several security issues and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=30608 - https://webkitgtk.org/2022/07/05/webkitgtk2.36.4-released.html - https://webkitgtk.org/security/WSA-2022-0006.html - https://www.cve.org/CVERecord?id=CVE-2022-22662 - https://www.cve.org/CVERecord?id=CVE-2022-22677 - https://www.cve.org/CVERecord?id=CVE-2022-26710 SRPMS: - 8/core/webkit2-2.36.4-1.mga8 . MGASA-2022-0255 pertains to important vulnerabilities in the webkit2 components for Mageia 8. Prompt attention is necessary.. Mageia Security Advisory, webkit2 Update, Mageia Package Fix, Webkit Vulnerability. . Severity: Critical. LinuxSecurity.com Team
The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22624 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5116-1
* get rid of webkit1/webkitgtk3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f17c8c6aaf 2016-09-27 00:29:22.123650 -------------------------------------------------------------------------------- Name : vfrnav Product : Fedora 25 Version : 20160429 Release : 1.fc25 URL : Summary : VFR/IFR Navigation Description : This is a navigation application for VFR and IFR flying. -------------------------------------------------------------------------------- Update Information: * get rid of webkit1/webkitgtk3 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update vfrnav' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Multiple security vulnerabilities were fixed in WebKit.. =========================================================================Ubuntu Security Notice USN-1617-1 October 25, 2012 webkit vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Multiple security vulnerabilities were fixed in WebKit. Software Description: - webkit: Web content engine library for GTK+ Details: A large number of security issues were discovered in the WebKit browser and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libjavascriptcoregtk-1.0-0 1.8.3-0ubuntu0.12.04.1 libjavascriptcoregtk-3.0-0 1.8.3-0ubuntu0.12.04.1 libwebkitgtk-1.0-0 1.8.3-0ubuntu0.12.04.1 libwebkitgtk-3.0-0 1.8.3-0ubuntu0.12.04.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1617-1 CVE-2011-3031, CVE-2011-3038, CVE-2011-3042, CVE-2011-3043, CVE-2011-3044, CVE-2011-3051, CVE-2011-3053, CVE-2011-3059, CVE-2011-3060, CVE-2011-3064, CVE-2011-3067, CVE-2011-3076, CVE-2011-3081, CVE-2011-3086, CVE-2011-3090, CVE-2012-1521, CVE-2012-3598, CVE-2012-3601, CVE-2012-3604, CVE-2012-3611, CVE-2012-3612, CVE-2012-3617, CVE-2012-3625, CVE-2012-3626, CVE-2012-3627, CVE-2012-3628, CVE-2012-3645, CVE-2012-3652, CVE-2012-3657, CVE-2012-3669, CVE-2012-3670, CVE-2012-3671, CVE-2012-3672, CVE-2012-3674, CVE-2012-3674, https://bugs.launchpad.net/ubuntu/+source/webkit/+bug/1058339 PackageInformation: https://launchpad.net/ubuntu/+source/webkit/1.8.3-0ubuntu0.12.04.1 . A series of WebKit security flaws have been patched in Ubuntu 12.04 LTS, enhancing browser safety. Ensure you update to safeguard your system.. WebKit Exploit Fix, Ubuntu Security Update, Browser Security Patch. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.