MGASA-2026-0064 - Updated webkit2 packages fix security vulnerabilities. MGASA-2026-0064 - Updated webkit2 packages fix security vulnerabilities Publication date: 24 Mar 2026 URL: https://advisories.mageia.org/MGASA-2026-0064.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-43457, CVE-2026-20608, CVE-2026-20635, CVE-2026-20636, CVE-2026-20644, CVE-2026-20652, CVE-2026-20676 Description: CVE-2025-43457 Processing maliciously crafted web content may lead to an unexpected Safari crash. A use-after-free issue was addressed with improved memory management. CVE-2026-20608 Processing maliciously crafted web content may lead to an unexpected process crash. This issue was addressed through improved state management. CVE-2026-20635 Processing maliciously crafted web content may lead to an unexpected process crash. The issue was addressed with improved memory handling. CVE-2026-20636 Processing maliciously crafted web content may lead to an unexpected process crash. The issue was addressed with improved memory handling. CVE-2026-20644 Processing maliciously crafted web content may lead to an unexpected process crash. The issue was addressed with improved memory handling. CVE-2026-20652 A remote attacker may be able to cause a denial-of-service. The issue was addressed with improved memory handling. CVE-2026-20676 A website may be able to track users through Safari web extensions. This issue was addressed through improved state management. References: - https://bugs.mageia.org/show_bug.cgi?id=35228 - https://webkitgtk.org/2026/03/12/webkitgtk2.50.6-released.html - https://webkitgtk.org/security/WSA-2026-0001.html - https://www.cve.org/CVERecord?id=CVE-2025-43457 - https://www.cve.org/CVERecord?id=CVE-2026-20608 - https://www.cve.org/CVERecord?id=CVE-2026-20635 - https://www.cve.org/CVERecord?id=CVE-2026-20636 - https://www.cve.org/CVERecord?id=CVE-2026-20644 - https://www.cve.org/CVERecord?id=CVE-2026-20652 - https://www.cve.org/CVERecord?id=CVE-2026-20676 SRPMS: -9/core/webkit2-2.50.6-1.mga9 . Updated webkit2 packages in Mageia address critical issues leading to crashes and denial of service, ensuring better security.. Mageia security advisory, webkit2 update, critical vulnerabilities, denial of service fixes. . Severity: Critical. LinuxSecurity.com Team
MGAA-2026-0015 - Updated webkit2 packages fix bug. MGAA-2026-0015 - Updated webkit2 packages fix bug Publication date: 22 Feb 2026 URL: https://advisories.mageia.org/MGAA-2026-0015.html Type: bugfix Affected Mageia releases: 9 Description: The updated packages fix several crashes and rendering issues. References: - https://bugs.mageia.org/show_bug.cgi?id=35144 - https://webkitgtk.org/2026/02/09/webkitgtk2.50.5-released.html SRPMS: - 9/core/webkit2-2.50.5-1.mga9 . Updated webkit2 packages resolve crashes and rendering issues in Mageia, enhancing system stability and reliability.. webkit2 bug fix Mageia stability updates. . Severity: Critical. LinuxSecurity.com Team
MGASA-2025-0331 - Updated webkit2 packages fix security vulnerabilities. MGASA-2025-0331 - Updated webkit2 packages fix security vulnerabilities Publication date: 21 Dec 2025 URL: https://advisories.mageia.org/MGASA-2025-0331.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-43501, CVE-2025-43531, CVE-2025-43535, CVE-2025-43536 Description: CVE-2025-43501 Processing maliciously crafted web content may lead to an unexpected process crash. Description: A buffer overflow issue was addressed with improved memory handling. VE-2025-43531Processing maliciously crafted web content may lead to an unexpected process crash. Description: A race condition was addressed with improved state handling. CVE-2025-43535 Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling. CVE-2025-43536 Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. References: - https://bugs.mageia.org/show_bug.cgi?id=34866 - https://webkitgtk.org/security/WSA-2025-0010.html - https://webkitgtk.org/2025/12/16/webkitgtk2.50.4-released.html - https://www.cve.org/CVERecord?id=CVE-2025-43501 - https://www.cve.org/CVERecord?id=CVE-2025-43531 - https://www.cve.org/CVERecord?id=CVE-2025-43535 - https://www.cve.org/CVERecord?id=CVE-2025-43536 SRPMS: - 9/core/webkit2-2.50.4-1.mga9 . Updated webkit2 packages in Mageia resolve critical memory handling concerns leading to crashes.. Mageia Security Advisory, webkit2 update, memory handling issue, buffer overflow fixes. . Severity: Important. LinuxSecurity.com Team
MGASA-2025-0319 - Updated webkit2 packages fix security vulnerabilities. MGASA-2025-0319 - Updated webkit2 packages fix security vulnerabilities Publication date: 04 Dec 2025 URL: https://advisories.mageia.org/MGASA-2025-0319.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-43392, CVE-2025-43419, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429, CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434, CVE-2025-43440, CVE-2025-43443, CVE-2025-43421 Description: The updated packages fix security vulnerabilities: CVE-2025-43392, CVE-2025-43419, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429, CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434, CVE-2025-43440, CVE-2025-43443, CVE-2025-43421. References: - https://bugs.mageia.org/show_bug.cgi?id=34792 - https://webkitgtk.org/security/WSA-2025-0008.html - https://webkitgtk.org/2025/11/19/webkitgtk2.50.2-released.html - https://www.cve.org/CVERecord?id=CVE-2025-43392 - https://www.cve.org/CVERecord?id=CVE-2025-43419 - https://www.cve.org/CVERecord?id=CVE-2025-43425 - https://www.cve.org/CVERecord?id=CVE-2025-43427 - https://www.cve.org/CVERecord?id=CVE-2025-43429 - https://www.cve.org/CVERecord?id=CVE-2025-43430 - https://www.cve.org/CVERecord?id=CVE-2025-43431 - https://www.cve.org/CVERecord?id=CVE-2025-43432 - https://www.cve.org/CVERecord?id=CVE-2025-43434 - https://www.cve.org/CVERecord?id=CVE-2025-43440 - https://www.cve.org/CVERecord?id=CVE-2025-43443 - https://www.cve.org/CVERecord?id=CVE-2025-43421 SRPMS: - 9/core/webkit2-2.50.2-1.mga9 . Updated webkit2 packages for Mageia address important security concerns fixed for CVE-2025-43392 and others.. Mageia security advisory, webkit2 updates, CVE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
MGASA-2025-0313 - Updated webkit2 packages fix security vulnerabilities. MGASA-2025-0313 - Updated webkit2 packages fix security vulnerabilities Publication date: 25 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0313.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-23271, CVE-2024-27808, CVE-2024-27820, CVE-2024-27833, CVE-2024-40866, CVE-2024-44187, CVE-2024-44185, CVE-2024-44244, CVE-2024-44296, CVE-2024-44308, CVE-2024-54479, CVE-2024-54502, CVE-2024-54505, CVE-2024-54534, CVE-2024-27856, CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162, CVE-2024-44192, CVE-2024-54467, CVE-2025-24201, CVE-2024-54551, CVE-2025-24208, CVE-2025-24209, CVE-2025-24213, CVE-2025-24216, CVE-2025-24264, CVE-2025-30427, CVE-2025-24223, CVE-2025-31204, CVE-2025-31205, CVE-2025-31206, CVE-2025-31215, CVE-2025-31257, CVE-2025-24189, CVE-2025-31273, CVE-2025-31278, CVE-2025-43211, CVE-2025-43212, CVE-2025-43216, CVE-2025-43227, CVE-2025-43228, CVE-2025-43240, CVE-2025-43265, CVE-2025-6558, CVE-2025-43272, CVE-2025-43342, CVE-2025-43356, CVE-2025-43368, CVE-2025-43343 Description: We are updating webkit2 to version 2.50.1 that has many security fixes since our current version. Please see the links for additional information References: - https://bugs.mageia.org/show_bug.cgi?id=34747 - https://webkitgtk.org/2025/10/10/webkitgtk2.50.1-released.html - https://webkitgtk.org/security/WSA-2025-0007.html - https://webkitgtk.org/2025/09/17/webkitgtk2.50.0-released.html - https://webkitgtk.org/security/WSA-2025-0006.html - https://webkitgtk.org/2025/07/31/webkitgtk2.49.4-released.html - https://webkitgtk.org/2025/09/03/webkitgtk2.48.6-released.html - https://webkitgtk.org/2025/08/01/webkitgtk2.48.5-released.html -https://webkitgtk.org/security/WSA-2025-0005.html - https://webkitgtk.org/2025/05/28/webkitgtk2.48.3-released.html - https://webkitgtk.org/2025/05/14/webkitgtk2.48.2-released.html - https://www.cve.org/CVERecord?id=CVE-2024-23271 - https://www.cve.org/CVERecord?id=CVE-2024-27808 - https://www.cve.org/CVERecord?id=CVE-2024-27820 - https://www.cve.org/CVERecord?id=CVE-2024-27833 - https://www.cve.org/CVERecord?id=CVE-2024-40866 - https://www.cve.org/CVERecord?id=CVE-2024-44187 - https://www.cve.org/CVERecord?id=CVE-2024-44185 - https://www.cve.org/CVERecord?id=CVE-2024-44244 - https://www.cve.org/CVERecord?id=CVE-2024-44296 - https://www.cve.org/CVERecord?id=CVE-2024-44308 - https://www.cve.org/CVERecord?id=CVE-2024-54479 - https://www.cve.org/CVERecord?id=CVE-2024-54502 - https://www.cve.org/CVERecord?id=CVE-2024-54505 - https://www.cve.org/CVERecord?id=CVE-2024-54534 - https://www.cve.org/CVERecord?id=CVE-2024-27856 - https://www.cve.org/CVERecord?id=CVE-2024-54543 - https://www.cve.org/CVERecord?id=CVE-2025-24143 - https://www.cve.org/CVERecord?id=CVE-2025-24150 - https://www.cve.org/CVERecord?id=CVE-2025-24158 - https://www.cve.org/CVERecord?id=CVE-2025-24162 - https://www.cve.org/CVERecord?id=CVE-2024-44192 - https://www.cve.org/CVERecord?id=CVE-2024-54467 - https://www.cve.org/CVERecord?id=CVE-2025-24201 - https://www.cve.org/CVERecord?id=CVE-2024-54551 - https://www.cve.org/CVERecord?id=CVE-2025-24208 - https://www.cve.org/CVERecord?id=CVE-2025-24209 - https://www.cve.org/CVERecord?id=CVE-2025-24213 - https://www.cve.org/CVERecord?id=CVE-2025-24216 - https://www.cve.org/CVERecord?id=CVE-2025-24264 - https://www.cve.org/CVERecord?id=CVE-2025-30427 - https://www.cve.org/CVERecord?id=CVE-2025-24223 - https://www.cve.org/CVERecord?id=CVE-2025-31204 - https://www.cve.org/CVERecord?id=CVE-2025-31205 - https://www.cve.org/CVERecord?id=CVE-2025-31206 - https://www.cve.org/CVERecord?id=CVE-2025-31215 - https://www.cve.org/CVERecord?id=CVE-2025-31257 - https://www.cve.org/CVERecord?id=CVE-2025-24189 -https://www.cve.org/CVERecord?id=CVE-2025-31273 - https://www.cve.org/CVERecord?id=CVE-2025-31278 - https://www.cve.org/CVERecord?id=CVE-2025-43211 - https://www.cve.org/CVERecord?id=CVE-2025-43212 - https://www.cve.org/CVERecord?id=CVE-2025-43216 - https://www.cve.org/CVERecord?id=CVE-2025-43227 - https://www.cve.org/CVERecord?id=CVE-2025-43228 - https://www.cve.org/CVERecord?id=CVE-2025-43240 - https://www.cve.org/CVERecord?id=CVE-2025-43265 - https://www.cve.org/CVERecord?id=CVE-2025-6558 - https://www.cve.org/CVERecord?id=CVE-2025-43272 - https://www.cve.org/CVERecord?id=CVE-2025-43342 - https://www.cve.org/CVERecord?id=CVE-2025-43356 - https://www.cve.org/CVERecord?id=CVE-2025-43368 - https://www.cve.org/CVERecord?id=CVE-2025-43343 SRPMS: - 9/core/webkit2-2.50.1-1.2.mga9 . Updated webkit2 packages address multiple important security flaws affecting Mageia 9. Learn about the latest updates.. Mageia webkit2 security updates, webkit vulnerability fixes, Mageia important advisories. . Severity: Important. LinuxSecurity.com Team
MGASA-2025-0291 - Updated webkit2 packages fix security vulnerabilities. MGASA-2025-0291 - Updated webkit2 packages fix security vulnerabilities Publication date: 14 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0291.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-27838, CVE-2024-27851, CVE-2024-40776, CVE-2024-40779, CVE-2024-40780, CVE-2024-40782, CVE-2024-40789, CVE-2024-4558 Description: CVE-2024-27838 A maliciously crafted webpage may be able to fingerprint the user. Description: The issue was addressed by adding additional logic. CVE-2024-27851 Processing maliciously crafted web content may lead to arbitrary code execution. Description: The issue was addressed with improved bounds checks. CVE-2024-40776 Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. CVE-2024-40779 / CVE-2024-40780 Processing maliciously crafted web content may lead to an unexpected process crash. Description: An out-of-bounds read was addressed with improved bounds checking. CVE-2024-40782 Processing maliciously crafted web content may lead to an unexpected process crash. Description: A use-after-free issue was addressed with improved memory management. CVE-2024-40789 Processing maliciously crafted web content may lead to an unexpected process crash. Description: An out-of-bounds access issue was addressed with improved bounds checking. CVE-2024-4558 Processing maliciously crafted web content may lead to an unexpected process crash. Description: Use after free in ANGLE allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. References: - https://bugs.mageia.org/show_bug.cgi?id=33513 - https://webkitgtk.org/release/webkitgtk-2.44.4.html - https://webkitgtk.org/2024/08/13/webkitgtk2.44.3-released.html - https://webkitgtk.org/security/WSA-2024-0004.html - https://www.cve.org/CVERecord?id=CVE-2024-27838 -https://www.cve.org/CVERecord?id=CVE-2024-27851 - https://www.cve.org/CVERecord?id=CVE-2024-40776 - https://www.cve.org/CVERecord?id=CVE-2024-40779 - https://www.cve.org/CVERecord?id=CVE-2024-40780 - https://www.cve.org/CVERecord?id=CVE-2024-40782 - https://www.cve.org/CVERecord?id=CVE-2024-40789 - https://www.cve.org/CVERecord?id=CVE-2024-4558 SRPMS: - 9/core/webkit2-2.44.4-1.mga9 . Updated webkit2 packages in Mageia fix critical threats and improve stability. Essential patch for safe browsing.. Mageia webkit2 security update, security advisory, important patches. . Severity: Important. LinuxSecurity.com Team
The updated packages fix a security vulnerability and other issues. References: - https://bugs.mageia.org/show_bug.cgi?id=33232 - https://webkitgtk.org/security/WSA-2024-0003.html . MGASA-2024-0208 - Updated webkit2 packages fix security vulnerabilities Publication date: 03 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0208.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-27834 The updated packages fix a security vulnerability and other issues. References: - https://bugs.mageia.org/show_bug.cgi?id=33232 - https://webkitgtk.org/security/WSA-2024-0003.html - https://webkitgtk.org/2024/05/16/webkitgtk2.44.2-released.html - https://ubuntu.com/security/notices/USN-6788-1 - https://www.cve.org/CVERecord?id=CVE-2024-27834 SRPMS: - 9/core/webkit2-2.44.2-1.mga9 . Mageia's recent updates to the webkit2 packages tackle critical security flaws and offer detailed resolutions, alongside security patch explanations and documentation. Mageia Security Advisory, Webkit2 Update, Critical Fixes, Mageia Software. . Severity: Critical. LinuxSecurity.com Team
Due to issues in our build system this package is very outdated, now that the issues are fixed we are publishing the current upstream version. Lot of CVEs are fixed and a lot of changes were made by upstream, see the links. . MGASA-2024-0148 - Updated webkit2 packages fix security vulnerabilities Publication date: 26 Apr 2024 URL: https://advisories.mageia.org/MGASA-2024-0148.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-37450, CVE-2023-38133, CVE-2023-38572, CVE-2023-38592, CVE-2023-38594, CVE-2023-38595, CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611, CVE-2023-40397, CVE-2023-39928, CVE-2023-39434, CVE-2023-40451, CVE-2023-41074, CVE-2023-41993, CVE-2023-42916, CVE-2023-42917, CVE-2023-42883, CVE-2023-42890, CVE-2024-23222, CVE-2024-23206, CVE-2024-23213, CVE-2023-40414, CVE-2014-1745, CVE-2024-23252, CVE-2024-23254, CVE-2024-23263, CVE-2024-23280, CVE-2024-23284, CVE-2023-42950, CVE-2023-42956, CVE-2023-42843 Due to issues in our build system this package is very outdated, now that the issues are fixed we are publishing the current upstream version. Lot of CVEs are fixed and a lot of changes were made by upstream, see the links. References: - https://bugs.mageia.org/show_bug.cgi?id=32202 - https://webkitgtk.org/2024/04/09/webkitgtk2.44.1-released.html - https://webkitgtk.org/2024/03/16/webkitgtk2.44.0-released.html - https://webkitgtk.org/2024/02/02/webkitgtk2.43.4-released.html - https://webkitgtk.org/2024/02/05/webkitgtk2.42.5-released.html - https://webkitgtk.org/2024/02/02/webkitgtk2.43.4-released.html - https://webkitgtk.org/2023/12/21/webkitgtk2.43.3-released.html - https://webkitgtk.org/2023/12/15/webkitgtk2.42.4-released.html - https://webkitgtk.org/2023/12/05/webkitgtk2.42.3-released.html -https://webkitgtk.org/2023/11/17/webkitgtk2.43.1-released.html - https://webkitgtk.org/2023/11/10/webkitgtk2.42.2-released.html - https://webkitgtk.org/2023/09/15/webkitgtk2.42.0-released.html - https://webkitgtk.org/2023/09/08/webkitgtk2.41.92-released.html - https://webkitgtk.org/2023/08/19/webkitgtk2.41.91-released.html - https://webkitgtk.org/2023/08/10/webkitgtk2.41.90-released.html - https://webkitgtk.org/2023/08/01/webkitgtk2.40.5-released.html - https://webkitgtk.org/2023/07/21/webkitgtk2.40.4-released.html - https://webkitgtk.org/2023/07/04/webkitgtk2.41.6-released.html - https://www.cve.org/CVERecord?id=CVE-2023-37450 - https://www.cve.org/CVERecord?id=CVE-2023-38133 - https://www.cve.org/CVERecord?id=CVE-2023-38572 - https://www.cve.org/CVERecord?id=CVE-2023-38592 - https://www.cve.org/CVERecord?id=CVE-2023-38594 - https://www.cve.org/CVERecord?id=CVE-2023-38595 - https://www.cve.org/CVERecord?id=CVE-2023-38597 - https://www.cve.org/CVERecord?id=CVE-2023-38599 - https://www.cve.org/CVERecord?id=CVE-2023-38600 - https://www.cve.org/CVERecord?id=CVE-2023-38611 - https://www.cve.org/CVERecord?id=CVE-2023-40397 - https://www.cve.org/CVERecord?id=CVE-2023-39928 - https://www.cve.org/CVERecord?id=CVE-2023-39434 - https://www.cve.org/CVERecord?id=CVE-2023-40451 - https://www.cve.org/CVERecord?id=CVE-2023-41074 - https://www.cve.org/CVERecord?id=CVE-2023-41993 - https://www.cve.org/CVERecord?id=CVE-2023-42916 - https://www.cve.org/CVERecord?id=CVE-2023-42917 - https://www.cve.org/CVERecord?id=CVE-2023-42883 - https://www.cve.org/CVERecord?id=CVE-2023-42890 - https://www.cve.org/CVERecord?id=CVE-2024-23222 - https://www.cve.org/CVERecord?id=CVE-2024-23206 - https://www.cve.org/CVERecord?id=CVE-2024-23213 - https://www.cve.org/CVERecord?id=CVE-2023-40414 - https://www.cve.org/CVERecord?id=CVE-2014-1745 - https://www.cve.org/CVERecord?id=CVE-2024-23252 - https://www.cve.org/CVERecord?id=CVE-2024-23254 - https://www.cve.org/CVERecord?id=CVE-2024-23263 -https://www.cve.org/CVERecord?id=CVE-2024-23280 - https://www.cve.org/CVERecord?id=CVE-2024-23284 - https://www.cve.org/CVERecord?id=CVE-2023-42950 - https://www.cve.org/CVERecord?id=CVE-2023-42956 - https://www.cve.org/CVERecord?id=CVE-2023-42843 SRPMS: - 9/core/webkit2-2.44.1-1.mga9 . Newly released webkit2 updates tackle various vulnerabilities, significantly boosting Mageia's resilience and security protocols.. Mageia 9 Security Issues, Webkit2 Updates, Security Patches. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.