[Git][security-tracker-team/security-tracker][master] webkit2gtk / wpewebkit upstream advisory WSA-2026-0005

Alberto Garcia (@berto) berto at debian.org
Thu Aug 20 11:47:59 BST 2026



Alberto Garcia pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4b86f603 by Alberto Garcia at 2026-08-20T11:16:22+02:00
webkit2gtk / wpewebkit upstream advisory WSA-2026-0005

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -4868,7 +4868,14 @@ CVE-2026-64849 (MLflow is an open source AI engineering platform for agents, lar
 CVE-2026-64788 (The issue was addressed with improved memory handling. This issue is f ...)
 	NOT-FOR-US: Apple
 CVE-2026-64787 (A use-after-free issue was addressed with improved memory management.  ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.5-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.5-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-64784 (An out-of-bounds access issue was addressed with improved bounds check ...)
 	NOT-FOR-US: Apple
 CVE-2026-64782 (A memory corruption vulnerability was addressed with improved locking. ...)
@@ -4967,7 +4974,14 @@ CVE-2026-34398 (FreeCAD is a free and open-source multiplatform 3D parametric mo
 	NOTE: https://github.com/FreeCAD/FreeCAD/pull/28610
 	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/9ed351cc4700db0a94c46f020c34c58bbf1bdaba (1.1.1)
 CVE-2026-28984 (The issue was addressed with improved memory handling. This issue is f ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.4-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.4-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-19589 (Packer up to 1.15.4 is vulnerable to an issue in the third-party plugi ...)
@@ -28155,7 +28169,14 @@ CVE-2026-65438 (Unauthenticated Cross Site Scripting (XSS) in Message Filter for
 CVE-2026-65437 (Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpa ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-64783 (A use-after-free issue was addressed with improved memory management.  ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.6-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.6-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-64776 (The issue was addressed with improved bounds checks. This issue is fix ...)
 	NOT-FOR-US: Apple
 CVE-2026-64775 (A memory initialization issue was addressed with improved memory handl ...)
@@ -28187,7 +28208,14 @@ CVE-2026-64762 (An out-of-bounds read was addressed with improved bounds checkin
 CVE-2026-64758 (The issue was addressed with improved bounds checks. This issue is fix ...)
 	NOT-FOR-US: Apple
 CVE-2026-64757 (A memory corruption issue was addressed with improved state management ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.6-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.6-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-64755 (An authorization issue was addressed with improved state management. T ...)
 	NOT-FOR-US: Apple
 CVE-2026-64754 (An out-of-bounds write issue was addressed with improved bounds checki ...)
@@ -28229,11 +28257,25 @@ CVE-2026-64732 (This issue was addressed through improved state management. This
 CVE-2026-64731 (A path handling issue was addressed with improved validation. This iss ...)
 	NOT-FOR-US: Apple
 CVE-2026-64730 (The issue was addressed with improved UI. This issue is fixed in Safar ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.6-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.6-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-64729 (A use after free issue was addressed with improved memory management.  ...)
 	NOT-FOR-US: Apple
 CVE-2026-64728 (A permissions issue was addressed with improved validation. This issue ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.6-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.6-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-64727 (A type confusion issue was addressed with improved memory handling. Th ...)
 	NOT-FOR-US: Apple
 CVE-2026-64726 (The issue was addressed with improved memory handling. This issue is f ...)
@@ -28251,13 +28293,27 @@ CVE-2026-64721 (This issue was addressed through improved state management. This
 CVE-2026-64720 (A race condition was addressed with improved state handling. This issu ...)
 	NOT-FOR-US: Apple
 CVE-2026-64719 (An out-of-bounds access issue was addressed with improved bounds check ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.6-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.6-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-64718 (A use-after-free issue was addressed with improved memory management.  ...)
 	NOT-FOR-US: Apple
 CVE-2026-64716 (The issue was addressed with improved memory handling. This issue is f ...)
 	NOT-FOR-US: Apple
 CVE-2026-64713 (This issue was addressed with improved checks. This issue is fixed in  ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.6-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.6-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-64711 (This issue was addressed with additional entitlement checks. This issu ...)
 	NOT-FOR-US: Apple
 CVE-2026-64710 (A privacy issue was addressed by removing sensitive data. This issue i ...)
@@ -28365,7 +28421,14 @@ CVE-2026-43806 (A denial of service issue was addressed by removing the vulnerab
 CVE-2026-43805 (A race condition was addressed with improved state handling. This issu ...)
 	NOT-FOR-US: Apple
 CVE-2026-43804 (This issue was addressed through improved state management. This issue ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.52.6-1
+	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+	[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+	- wpewebkit 2.52.6-1
+	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <end-of-life> (see #1035997)
+	NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
 CVE-2026-43803 (An out-of-bounds write issue was addressed with improved bounds checki ...)
 	NOT-FOR-US: Apple
 CVE-2026-43802 (An out-of-bounds write issue was addressed with improved bounds checki ...)


=====================================
data/DSA/list
=====================================
@@ -155,7 +155,7 @@
 	{CVE-2026-60137}
 	[trixie] - wordpress 6.8.6+dfsg1-0+deb13u1
 [23 Jul 2026] DSA-6398-1 webkit2gtk - security update
-	{CVE-2024-4367 CVE-2026-28847 CVE-2026-28883 CVE-2026-28901 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-39872 CVE-2026-43658 CVE-2026-43660 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745}
+	{CVE-2024-4367 CVE-2026-28847 CVE-2026-28883 CVE-2026-28901 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-28984 CVE-2026-39872 CVE-2026-43658 CVE-2026-43660 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745 CVE-2026-64787}
 	[trixie] - webkit2gtk 2.52.5-1~deb13u1
 [23 Jul 2026] DSA-6397-1 pdns-recursor - security update
 	{CVE-2026-52686 CVE-2026-52688}


=====================================
data/dsa-needed.txt
=====================================
@@ -166,6 +166,8 @@ vim
 --
 vips
 --
+webkit2gtk (berto)
+--
 weechat
   Upstream recommends to use branch from https://github.com/weechat/weechat/commits/4.6/, cf #1142597
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b86f603e398f1ffb6514ffca77143edb813f245

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b86f603e398f1ffb6514ffca77143edb813f245
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/a7bdfa5e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list