RLSA-2026:69098

Source
https://errata.rockylinux.org/RLSA-2026:69098
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:69098.json
JSON Data
https://api.test.osv.dev/v1/vulns/RLSA-2026:69098
Upstream
CVE (116)
  • CVE-2023-4860
  • CVE-2024-7966
  • CVE-2024-8193
  • CVE-2024-8198
  • CVE-2024-8636
  • CVE-2024-9123
  • CVE-2025-0436
  • CVE-2025-0444
  • CVE-2026-10009
  • CVE-2026-10011
  • CVE-2026-10012
  • CVE-2026-10020
  • CVE-2026-10925
  • CVE-2026-10941
  • CVE-2026-10977
  • CVE-2026-10985
  • CVE-2026-10993
  • CVE-2026-11024
  • CVE-2026-11039
  • CVE-2026-11057
  • CVE-2026-11099
  • CVE-2026-11121
  • CVE-2026-11124
  • CVE-2026-11159
  • CVE-2026-11663
  • CVE-2026-11675
  • CVE-2026-13781
  • CVE-2026-13820
  • CVE-2026-13841
  • CVE-2026-13885
  • CVE-2026-13971
  • CVE-2026-14387
  • CVE-2026-14389
  • CVE-2026-14410
  • CVE-2026-14414
  • CVE-2026-14419
  • CVE-2026-14427
  • CVE-2026-14429
  • CVE-2026-15766
  • CVE-2026-15774
  • CVE-2026-16417
  • CVE-2026-17653
  • CVE-2026-17702
  • CVE-2026-17712
  • CVE-2026-17745
  • CVE-2026-17757
  • CVE-2026-17771
  • CVE-2026-17914
  • CVE-2026-17992
  • CVE-2026-19154
  • CVE-2026-19160
  • CVE-2026-19161
  • CVE-2026-19173
  • CVE-2026-19176
  • CVE-2026-28984
  • CVE-2026-3538
  • CVE-2026-3909
  • CVE-2026-3931
  • CVE-2026-43795
  • CVE-2026-43804
  • CVE-2026-4460
  • CVE-2026-5870
  • CVE-2026-6298
  • CVE-2026-6364
  • CVE-2026-64713
  • CVE-2026-64715
  • CVE-2026-64718
  • CVE-2026-64728
  • CVE-2026-64730
  • CVE-2026-64753
  • CVE-2026-64757
  • CVE-2026-64778
  • CVE-2026-64779
  • CVE-2026-64780
  • CVE-2026-64782
  • CVE-2026-64783
  • CVE-2026-64784
  • CVE-2026-64787
  • CVE-2026-65331
  • CVE-2026-65332
  • CVE-2026-65334
  • CVE-2026-65335
  • CVE-2026-65336
  • CVE-2026-65337
  • CVE-2026-65338
  • CVE-2026-65340
  • CVE-2026-65341
  • CVE-2026-65351
  • CVE-2026-7353
  • CVE-2026-76041
  • CVE-2026-78376
  • CVE-2026-78914
  • CVE-2026-78958
  • CVE-2026-79020
  • CVE-2026-79112
  • CVE-2026-79144
  • CVE-2026-79147
  • CVE-2026-7920
  • CVE-2026-7923
  • CVE-2026-7949
  • CVE-2026-83596
  • CVE-2026-84359
  • CVE-2026-84635
  • CVE-2026-85049
  • CVE-2026-8510
  • CVE-2026-8579
  • CVE-2026-91733
  • CVE-2026-91740
  • CVE-2026-91747
  • CVE-2026-9892
  • CVE-2026-9893
  • CVE-2026-9909
  • CVE-2026-9923
  • CVE-2026-9981
  • CVE-2026-9983
  • CVE-2026-9998
Published
2026-09-22T18:04:11Z
Modified
2026-09-22T18:24:42Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Important: webkit2gtk3 security update
Details

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)

  • chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)

  • chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)

  • chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)

  • chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)

  • webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)

  • webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)

  • webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)

  • webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)

  • webkitgtk: use-after-free of JSCValue function parameters (CVE-2026-78376)

  • chromium-browser: Skia: Information disclosure via out-of-bounds read in crafted media file (CVE-2026-79020)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-43795)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2026-64715)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64718)

  • webkitgtk: Visiting a maliciously crafted website may leak sensitive data (CVE-2026-64778)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64779)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64780)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64782)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64784)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65331)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65332)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65334)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65335)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65336)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65337)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65338)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65340)

  • webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2026-65341)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-65351)

  • webkitgtk: Validate the full FeatureList array once in OpenTypeVerticalData findFeature (CVE-2026-83596)

  • chromium-browser: skia: chromium-browser: Information leak in Skia (CVE-2026-84359)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-84635)

  • webkitgtk: Processing maliciously crafted web content may disclose sensitive user information (CVE-2026-64753)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Database specific
{
    "license":  "CC-BY-4.0",
    "license_url":  "https://creativecommons.org/licenses/by/4.0/",
    "source_advisory":  "RHSA-2026:69098"
}
References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:9 / webkit2gtk3

Package

Name
webkit2gtk3
Purl
pkg:rpm/rocky-linux/webkit2gtk3?distro=rocky-linux-9&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0:2.54.0-1.el9_8
Database specific
Show details
{
    "yum_repository":  "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:69098.json"