Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 74 articles for you...
87

Debian WebKitGTK Critical CVE-2025-46299 App Disclosure March 2026

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-46299 Google Big Sleep discovered that processing maliciously crafted web content may disclose internal states of the app.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6232-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alberto Garcia April 28, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit2gtk CVE ID : CVE-2025-46299 CVE-2026-20643 CVE-2026-20664 CVE-2026-20665 CVE-2026-20691 CVE-2026-28857 CVE-2026-28859 CVE-2026-28861 CVE-2026-28871 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-46299 Google Big Sleep discovered that processing maliciously crafted web content may disclose internal states of the app. CVE-2026-20643 Thomas Espach discovered that processing maliciously crafted web content may bypass Same Origin Policy. CVE-2026-20664 Daniel Rhea, Soehnke Benedikt Fischedick, Emrovsky & Switch, and Yevhen Pervushyn discovered that processing maliciously crafted web content may lead to an unexpected process crash CVE-2026-20665 webb discovered that processing maliciously crafted web content may prevent Content Security Policy from being enforced. CVE-2026-20691 Gongyu Ma discovered that a maliciously crafted webpage may be able to fingerprint the user. CVE-2026-28857 Narcis Oliveras Fontas, Soehnke Benedikt Fischedick, Daniel Rhea, and Nathaniel Oh discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-28859 greenbynox and Arni Hardarson discovered that a malicious website may be able to process restricted web content outside the sandbox. CVE-2026-28861 Hongze Wu and ShuaikeDong discovered that a malicious website may be able to access script message handlers intended for other origins. CVE-2026-28871 @hamayanhamayan discovered that visiting a maliciously crafted website may lead to a cross- site scripting attack. Starting from version 2.52.0, WebKitGTK can no longer be backported to the oldstable distribution (bookworm). Because of that, the webkit2gtk packages are no longer covered by security support in bookworm. For the stable distribution (trixie), these problems have been fixed in version 2.52.1-1~deb13u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/webkit2gtk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . WebKitGTK faces critical issues allowing disclosure of internal states and XSS attacks; update recommended for Debian.. WebKitGTK security update, Debian DSA-6232-1, internal states disclosure, cross-site scripting attacks, security vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 28, 2026 Critical Debian
197

Debian 11 webkit2gtk Advisory DLA-4528-1 Multiple Crashes Denial of Service

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.. Debian LTS Advisory DLA-4528-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort April 11, 2026 https://wiki.debian.org/LTS Package : webkit2gtk Version : 2.50.6-1~deb11u1 CVE ID : CVE-2025-43214 CVE-2025-43457 CVE-2025-43511 CVE-2026-20608 CVE-2026-20635 CVE-2026-20636 CVE-2026-20644 CVE-2026-20652 CVE-2026-20676 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43457 Gary Kwong and Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43511 Lee Dong Ha discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-20608 HanQing and Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-20635 EntryHi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-20636 EntryHi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-20644 HanQing and Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2026-20652 Nathaniel Oh discovered that a remote attacker may be able to cause a denial-of-service. CVE-2026-20676 Tom Van Goethem discovered that a website may be able to track users through web extensions. For Debian 11 bullseye, these problems have been fixed inversion 2.50.6-1~deb11u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade webkit2gtk to mitigate multiple crashes and Denial of Service vulnerabilities identified in Debian LTS advisory DLA-4528-1.. Debian security advisory, webkit2gtk vulnerabilities, software update guide. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 11, 2026 Important Debian LTS
197

Debian 11: webkit2gtk Important App Crash Issues DLA-4399-1

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-13947 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4399-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort December 10, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : webkit2gtk Version : 2.50.3-1~deb11u1 CVE ID : CVE-2025-13947 CVE-2025-43421 CVE-2025-43458 CVE-2025-66287 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-13947 Janet Black discovered that a website may be able to exfiltrate sensitive system information. CVE-2025-43421 Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43458 Phil Beauvoir discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-66287 Stanislav Fort discovered that processing maliciously crafted web content may lead to an unexpected process crash. For Debian 11 bullseye, these problems have been fixed in version 2.50.3-1~deb11u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Discover critical updates for webkit2gtk in Debian due to vulnerabilities that may lead to data exfiltration and crashes.. Debian Security, WebKitGTK Update, CVE-2025-13947, Debian LTS Advisory, System Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 10, 2025 Important Debian LTS
87

Debian: webkit2gtk Critical Info Exfiltration DSA-6074-1 CVE-2025-13947

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-13947 Janet Black discovered that a website may be able to exfiltrate sensitive system information.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6074-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alberto Garcia December 09, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit2gtk CVE ID : CVE-2025-13947 CVE-2025-43421 CVE-2025-43458 CVE-2025-66287 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-13947 Janet Black discovered that a website may be able to exfiltrate sensitive system information. CVE-2025-43421 Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43458 Phil Beauvoir discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-66287 Stanislav Fort discovered that processing maliciously crafted web content may lead to an unexpected process crash. For the oldstable distribution (bookworm), these problems have been fixed in version 2.50.3-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 2.50.3-1~deb13u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical vulnerabilities in WebKitGTK allow potential system information exfiltration requiringurgent updates for Debian distributions.. WebKitGTK Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 09, 2025 Critical Debian
172

Ubuntu: WebKitGTK High Remote Code Execution Threat USN-7914-1

Several security issues were fixed in WebKitGTK.. ========================================================================== Ubuntu Security Notice USN-7914-1 December 08, 2025 webkit2gtk vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in WebKitGTK. Software Description: - webkit2gtk: Web content engine library for GTK+ Details: Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libjavascriptcoregtk-4.1-0 2.50.2-0ubuntu0.25.10.2 libjavascriptcoregtk-6.0-1 2.50.2-0ubuntu0.25.10.2 libwebkit2gtk-4.1-0 2.50.2-0ubuntu0.25.10.2 libwebkitgtk-6.0-4 2.50.2-0ubuntu0.25.10.2 Ubuntu 25.04 libjavascriptcoregtk-4.1-0 2.50.2-0ubuntu0.25.04.2 libjavascriptcoregtk-6.0-1 2.50.2-0ubuntu0.25.04.2 libwebkit2gtk-4.1-0 2.50.2-0ubuntu0.25.04.2 libwebkitgtk-6.0-4 2.50.2-0ubuntu0.25.04.2 Ubuntu 24.04 LTS libjavascriptcoregtk-4.1-0 2.50.2-0ubuntu0.24.04.2 libjavascriptcoregtk-6.0-1 2.50.2-0ubuntu0.24.04.2 libwebkit2gtk-4.1-0 2.50.2-0ubuntu0.24.04.2 libwebkitgtk-6.0-4 2.50.2-0ubuntu0.24.04.2 Ubuntu 22.04 LTS libjavascriptcoregtk-4.0-18 2.50.2-0ubuntu0.22.04.2 libjavascriptcoregtk-4.1-0 2.50.2-0ubuntu0.22.04.2 libjavascriptcoregtk-6.0-1 2.50.2-0ubuntu0.22.04.2 libwebkit2gtk-4.0-37 2.50.2-0ubuntu0.22.04.2 libwebkit2gtk-4.1-0 2.50.2-0ubuntu0.22.04.2 libwebkitgtk-6.0-4 2.50.2-0ubuntu0.22.04.2 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any applications that use WebKitGTK, such as Epiphany, to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7914-1 CVE-2025-43392, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429, CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434, CVE-2025-43440, CVE-2025-43443 Package Information: https://launchpad.net/ubuntu/+source/webkit2gtk/2.50.2-0ubuntu0.25.10.2 https://launchpad.net/ubuntu/+source/webkit2gtk/2.50.2-0ubuntu0.25.04.2 https://launchpad.net/ubuntu/+source/webkit2gtk/2.50.2-0ubuntu0.24.04.2 https://launchpad.net/ubuntu/+source/webkit2gtk/2.50.2-0ubuntu0.22.04.2 . Several security issues fixed in WebKitGTK for Ubuntu releases. Immediate updates are vital for system protection.. Ubuntu WebKitGTK security issues, web browser security vulnerabilities, update instructions for WebKitGTK. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 08, 2025 Important Ubuntu
197

Debian 11: Webkit2gtk Critical Security Update DLA-4394-1 CVE-2025-43392

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43392 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4394-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort December 04, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : webkit2gtk Version : 2.50.2-1~deb11u1 CVE ID : CVE-2025-43392 CVE-2025-43425 CVE-2025-43427 CVE-2025-43429 CVE-2025-43430 CVE-2025-43431 CVE-2025-43432 CVE-2025-43434 CVE-2025-43440 CVE-2025-43443 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43392 Tom Van Goethem discovered that a website may exfiltrate image data cross-origin. CVE-2025-43425 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43427 Gary Kwong and rheza discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43429 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43430 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43431 Google Big Sleep discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2025-43432 Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43434 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected browser crash. CVE-2025-43440 Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected processcrash. CVE-2025-43443 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. For Debian 11 bullseye, these problems have been fixed in version 2.50.2-1~deb11u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Critical vulnerabilities found in webkit2gtk require immediate upgrades for Debian 11 users to prevent crashes and data exfiltration.. Debian Security, Webkit2gtk Update, Critical Threat Detection, Debian 11 Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 04, 2025 Critical Debian LTS
87

Debian: WebKitGTK Critical CVE-2025-43392 Exfiltration and Crash DSA-6070-1

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43392 Tom Van Goethem discovered that a website may exfiltrate image data cross-origin.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6070-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Alberto Garcia December 04, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit2gtk CVE ID : CVE-2025-43392 CVE-2025-43425 CVE-2025-43427 CVE-2025-43429 CVE-2025-43430 CVE-2025-43431 CVE-2025-43432 CVE-2025-43434 CVE-2025-43440 CVE-2025-43443 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43392 Tom Van Goethem discovered that a website may exfiltrate image data cross-origin. CVE-2025-43425 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43427 Gary Kwong and rheza discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43429 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43430 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43431 Google Big Sleep discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2025-43432 Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43434 Google Big Sleep discovered that processing maliciously crafted web content may lead to an unexpected browser crash. CVE-2025-43440 Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43443 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. For the oldstable distribution (bookworm), these problems have been fixed in version 2.50.2-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 2.50.2-1~deb13u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple vulnerabilities discovered in WebKitGTK could allow image data exfiltration and process crashes, upgrade recommended.. Debian, WebKitGTK, Security Updates, Image Exfiltration, Process Crash. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 04, 2025 Critical Debian
197

Debian 11: Important Crash Advisory for WebKitGTK DLA-4375-1 CVE-2025-43272

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43272 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4375-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort November 20, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : webkit2gtk Version : 2.50.1-1~deb11u1 CVE ID : CVE-2025-43272 CVE-2025-43342 CVE-2025-43343 CVE-2025-43356 CVE-2025-43368 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43272 Big Bear discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43342 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43343 An anonymous researcher discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2025-43356 Jaydev Ahire discovered that a website may be able to access sensor information without user consent. CVE-2025-43368 Pawel Wylecial discovered that processing maliciously crafted web content may lead to an unexpected process crash. This WebKitGTK update causes a compatibility problem with older versions of Evolution when handling e-mail attachments. For this reason, fixed versions of Evolution have also been released along with this WebKitGTK update. For Debian 11 bullseye, these problems have been fixed in version 2.50.1-1~deb11u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian LTS security advisories, how to apply these updates toyour system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS DLA-4375-1 addresses multiple significant vulnerabilities in WebKitGTK that may cause unexpected crashes or sensor access.. Debian LTS, webkit2gtk, security update, process vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 20, 2025 Important Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200