DSA-6172-1 Unknown

DSA-6172-1 webkit2gtk - security update

Debian Released: March 21, 2026 Updated: March 27, 2026 Restart Required

Description

The following vulnerabilities have been discovered in the WebKitGTK web engine: <p> CVE-2025-43214 <p> shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash. <p> CVE-2025-43457 <p> Gary Kwong and Hossein Lotfi discovered that processing maliciously crafted web content may lead to an unexpected process crash. <p> CVE-2025-43511 <p> Lee Dong Ha discovered that processing maliciously crafted web content may lead to an unexpected process crash. <p> CVE-2026-20608 <p> HanQing and Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. <p> CVE-2026-20635 <p> EntryHi discovered that processing maliciously crafted web content may lead to an unexpected process crash. <p> CVE-2026-20636 <p> EntryHi discovered that processing maliciously crafted web content may lead to an unexpected process crash. <p> CVE-2026-20644 <p> HanQing and Nan Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash. <p> CVE-2026-20652 <p> Nathaniel Oh discovered that a remote attacker may be able to cause a denial-of-service. <p> CVE-2026-20676 <p> Tom Van Goethem discovered that a website may be able to track users through web extensions. <p> <a href="https://security-tracker.debian.org/tracker/DSA-6172-1">https://security-tracker.debian.org/tracker/DSA-6172-1</a>

Fixed Vulnerabilities 8

CVE-2026-20652 N/A 0.0 ⚠️ KEV fixed
Feb 11, 2026

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3,…

CVE-2025-43511 N/A 0.0 ⚠️ KEV fixed
Dec 12, 2025

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.2 and iPadOS…

CVE-2026-20635 N/A 0.0 ⚠️ KEV fixed
Feb 11, 2026

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3,…

CVE-2025-43457 N/A 0.0 ⚠️ KEV fixed
Nov 04, 2025

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS…

CVE-2026-20644 N/A 0.0 ⚠️ KEV fixed
Feb 11, 2026

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3,…

CVE-2026-20636 N/A 0.0 ⚠️ KEV fixed
Feb 11, 2026

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3.…

CVE-2026-20676 N/A 0.0 ⚠️ KEV fixed
Feb 11, 2026

This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3.…

CVE-2026-20608 N/A 0.0 ⚠️ KEV fixed
Feb 11, 2026

This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3,…

Quick Info

Patch ID: DSA-6172-1
Vendor: Debian
Severity: Unknown
CVEs Fixed: 8
Restart: Required

Vendor

Debian

Additional Info

dsa id: DSA-6172-1
rss link: https://lists.debian.org/debian-security-announce/2026/msg00081.html
rss title: DSA-6172-1 webkit2gtk - security update
dsa number: 6172-1
package name: webkit2gtk

Share