[Git][security-tracker-team/security-tracker][master] webkit2gtk / wpewebkit upstream advisory WSA-2026-0005
Alberto Garcia (@berto)
berto at debian.org
Thu Aug 20 11:47:59 BST 2026
Alberto Garcia pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4b86f603 by Alberto Garcia at 2026-08-20T11:16:22+02:00
webkit2gtk / wpewebkit upstream advisory WSA-2026-0005
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -4868,7 +4868,14 @@ CVE-2026-64849 (MLflow is an open source AI engineering platform for agents, lar
CVE-2026-64788 (The issue was addressed with improved memory handling. This issue is f ...)
NOT-FOR-US: Apple
CVE-2026-64787 (A use-after-free issue was addressed with improved memory management. ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.5-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.5-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-64784 (An out-of-bounds access issue was addressed with improved bounds check ...)
NOT-FOR-US: Apple
CVE-2026-64782 (A memory corruption vulnerability was addressed with improved locking. ...)
@@ -4967,7 +4974,14 @@ CVE-2026-34398 (FreeCAD is a free and open-source multiplatform 3D parametric mo
NOTE: https://github.com/FreeCAD/FreeCAD/pull/28610
NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/9ed351cc4700db0a94c46f020c34c58bbf1bdaba (1.1.1)
CVE-2026-28984 (The issue was addressed with improved memory handling. This issue is f ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.4-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.4-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-19589 (Packer up to 1.15.4 is vulnerable to an issue in the third-party plugi ...)
@@ -28155,7 +28169,14 @@ CVE-2026-65438 (Unauthenticated Cross Site Scripting (XSS) in Message Filter for
CVE-2026-65437 (Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpa ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-64783 (A use-after-free issue was addressed with improved memory management. ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.6-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.6-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-64776 (The issue was addressed with improved bounds checks. This issue is fix ...)
NOT-FOR-US: Apple
CVE-2026-64775 (A memory initialization issue was addressed with improved memory handl ...)
@@ -28187,7 +28208,14 @@ CVE-2026-64762 (An out-of-bounds read was addressed with improved bounds checkin
CVE-2026-64758 (The issue was addressed with improved bounds checks. This issue is fix ...)
NOT-FOR-US: Apple
CVE-2026-64757 (A memory corruption issue was addressed with improved state management ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.6-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.6-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-64755 (An authorization issue was addressed with improved state management. T ...)
NOT-FOR-US: Apple
CVE-2026-64754 (An out-of-bounds write issue was addressed with improved bounds checki ...)
@@ -28229,11 +28257,25 @@ CVE-2026-64732 (This issue was addressed through improved state management. This
CVE-2026-64731 (A path handling issue was addressed with improved validation. This iss ...)
NOT-FOR-US: Apple
CVE-2026-64730 (The issue was addressed with improved UI. This issue is fixed in Safar ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.6-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.6-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-64729 (A use after free issue was addressed with improved memory management. ...)
NOT-FOR-US: Apple
CVE-2026-64728 (A permissions issue was addressed with improved validation. This issue ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.6-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.6-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-64727 (A type confusion issue was addressed with improved memory handling. Th ...)
NOT-FOR-US: Apple
CVE-2026-64726 (The issue was addressed with improved memory handling. This issue is f ...)
@@ -28251,13 +28293,27 @@ CVE-2026-64721 (This issue was addressed through improved state management. This
CVE-2026-64720 (A race condition was addressed with improved state handling. This issu ...)
NOT-FOR-US: Apple
CVE-2026-64719 (An out-of-bounds access issue was addressed with improved bounds check ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.6-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.6-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-64718 (A use-after-free issue was addressed with improved memory management. ...)
NOT-FOR-US: Apple
CVE-2026-64716 (The issue was addressed with improved memory handling. This issue is f ...)
NOT-FOR-US: Apple
CVE-2026-64713 (This issue was addressed with improved checks. This issue is fixed in ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.6-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.6-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-64711 (This issue was addressed with additional entitlement checks. This issu ...)
NOT-FOR-US: Apple
CVE-2026-64710 (A privacy issue was addressed by removing sensitive data. This issue i ...)
@@ -28365,7 +28421,14 @@ CVE-2026-43806 (A denial of service issue was addressed by removing the vulnerab
CVE-2026-43805 (A race condition was addressed with improved state handling. This issu ...)
NOT-FOR-US: Apple
CVE-2026-43804 (This issue was addressed through improved state management. This issue ...)
- NOT-FOR-US: Apple
+ - webkit2gtk 2.52.6-1
+ [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
+ [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
+ - wpewebkit 2.52.6-1
+ [trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)
+ [bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+ [bullseye] - wpewebkit <end-of-life> (see #1035997)
+ NOTE: https://webkitgtk.org/security/WSA-2026-0005.html
CVE-2026-43803 (An out-of-bounds write issue was addressed with improved bounds checki ...)
NOT-FOR-US: Apple
CVE-2026-43802 (An out-of-bounds write issue was addressed with improved bounds checki ...)
=====================================
data/DSA/list
=====================================
@@ -155,7 +155,7 @@
{CVE-2026-60137}
[trixie] - wordpress 6.8.6+dfsg1-0+deb13u1
[23 Jul 2026] DSA-6398-1 webkit2gtk - security update
- {CVE-2024-4367 CVE-2026-28847 CVE-2026-28883 CVE-2026-28901 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-39872 CVE-2026-43658 CVE-2026-43660 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745}
+ {CVE-2024-4367 CVE-2026-28847 CVE-2026-28883 CVE-2026-28901 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-28984 CVE-2026-39872 CVE-2026-43658 CVE-2026-43660 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745 CVE-2026-64787}
[trixie] - webkit2gtk 2.52.5-1~deb13u1
[23 Jul 2026] DSA-6397-1 pdns-recursor - security update
{CVE-2026-52686 CVE-2026-52688}
=====================================
data/dsa-needed.txt
=====================================
@@ -166,6 +166,8 @@ vim
--
vips
--
+webkit2gtk (berto)
+--
weechat
Upstream recommends to use branch from https://github.com/weechat/weechat/commits/4.6/, cf #1142597
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b86f603e398f1ffb6514ffca77143edb813f245
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4b86f603e398f1ffb6514ffca77143edb813f245
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/a7bdfa5e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list