[CLSA-2026:1784988522] webkit2gtk3: Fix of 23 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-25 14:09:14 UTC
Description:
- Rebase to webkitgtk 2.52.5 (WebKitGTK Security Advisory WSA-2026-0004), aligning with the 2.52.x security baseline shipped by RHEL 9 (RHSA-2026:42062). - CVEs resolved by this rebase: CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745. - Drop fix-system-malloc-llint-extractor.patch; the upstream cherry-pick (WebKit 314364@main) is now included in 2.52.5. - Refresh libsoup2.patch for the 2.52.5 library version triplet bumps (WEBKIT 21/9/21, JAVASCRIPTCORE 10/13/10 on API 4.1; WEBKIT 20/9/16, JAVASCRIPTCORE 8/13/7 on API 6.0). The webkit2gtk-4.0 SONAME (libwebkit2gtk-4.0.so.37) is preserved.
Updated packages:
  • webkit2gtk3-2.52.5-1.el9.tuxcare.els10.x86_64.rpm
    sha:f90e962ed68d665e34003f56559912a74b8824fa904e12270cf95205f7948b59
  • webkit2gtk3-devel-2.52.5-1.el9.tuxcare.els10.x86_64.rpm
    sha:c0c6b6f8c73eefc1aa85a2ccb100691f1d19abea60a3b8f16562cb76f7ed2477
  • webkit2gtk3-jsc-2.52.5-1.el9.tuxcare.els10.x86_64.rpm
    sha:dc8c837a61382edd4ed3f457e1e8daf547746a1a7b59d654e3f3dd77a5f5c7a9
  • webkit2gtk3-jsc-devel-2.52.5-1.el9.tuxcare.els10.x86_64.rpm
    sha:f7a341c0196c4373d94cb68a209311bc942d841aca836d5587d6f3b7828ab00c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.