UbuntuUpdates.org

Package "webkit2gtk"

Name: webkit2gtk

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • WebKitGTK JavaScript command-line interpreter (transitional dummy package)
  • JavaScript engine library from WebKitGTK - development files
  • JavaScript engine library from WebKitGTK - development files
  • JavaScript engine library from WebKitGTK - command-line interpreter

Latest version: 2.52.6-0ubuntu0.24.04.1
Release: noble (24.04)
Level: security
Repository: universe

Links



Other versions of "webkit2gtk" in Noble

Repository Area Version
base universe 2.44.0-2
base main 2.44.0-2
security main 2.52.6-0ubuntu0.24.04.1
updates main 2.52.6-0ubuntu0.24.04.1
updates universe 2.52.6-0ubuntu0.24.04.1
proposed main 2.52.3-0ubuntu0.24.04.2
proposed universe 2.52.3-0ubuntu0.24.04.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.52.6-0ubuntu0.24.04.1 2026-08-31 14:07:49 UTC

webkit2gtk (2.52.6-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.52.6 to fix security issues.
    - CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902,
      CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907,
      CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953,
      CVE-2026-28955, CVE-2026-28958, CVE-2026-28984, CVE-2026-39872,
      CVE-2026-43658, CVE-2026-43660, CVE-2026-43663, CVE-2026-43676,
      CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707,
      CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716,
      CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726,
      CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734,
      CVE-2026-43740, CVE-2026-43742, CVE-2026-43745, CVE-2026-43804,
      CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730,
      CVE-2026-64757, CVE-2026-64783, CVE-2026-64787
  * Remove patches included in new version:
    - debian/patches/fix-atomics-detection.patch
    - debian/patches/fix-big-endian-string.patch

 -- Marc Deslauriers Fri, 21 Aug 2026 13:04:27 -0400

Source diff to previous version
CVE-2026-28847 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
CVE-2026-28883 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5,
CVE-2026-28901 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis
CVE-2026-28902 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis
CVE-2026-28903 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
CVE-2026-28904 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
CVE-2026-28905 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vis
CVE-2026-28907 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, m
CVE-2026-28942 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5,
CVE-2026-28946 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously cr
CVE-2026-28947 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 an
CVE-2026-28953 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
CVE-2026-28955 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, ma
CVE-2026-28958 This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5,
CVE-2026-28984 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5,
CVE-2026-39872 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26
CVE-2026-43658 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5,
CVE-2026-43660 A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, mac
CVE-2026-43663 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26
CVE-2026-43676 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS
CVE-2026-43699 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.
CVE-2026-43701 The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, mac
CVE-2026-43705 A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadO
CVE-2026-43707 A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Taho
CVE-2026-43712 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 2
CVE-2026-43713 A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.
CVE-2026-43715 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe
CVE-2026-43716 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Proces
CVE-2026-43720 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.
CVE-2026-43721 This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t
CVE-2026-43725 The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 2
CVE-2026-43726 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.
CVE-2026-43727 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.
CVE-2026-43731 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.
CVE-2026-43732 A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2,
CVE-2026-43734 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.
CVE-2026-43740 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 2
CVE-2026-43742 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.
CVE-2026-43745 An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS
CVE-2026-43804 This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS
CVE-2026-64713 This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26
CVE-2026-64719 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26
CVE-2026-64728 A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6
CVE-2026-64730 The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, w
CVE-2026-64757 A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6
CVE-2026-64783 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6,
CVE-2026-64787 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe

Version: 2.52.3-0ubuntu0.24.04.1 2026-05-06 16:07:58 UTC

  webkit2gtk (2.52.3-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.52.3 to fix security issues.
    - debian/libwebkit2gtk-4.0-37.symbols: added new symbols.
    - CVE-2025-43213, CVE-2025-43214, CVE-2025-43457, CVE-2025-43511,
      CVE-2025-46299, CVE-2026-20608, CVE-2026-20635, CVE-2026-20636,
      CVE-2026-20643, CVE-2026-20644, CVE-2026-20652, CVE-2026-20664,
      CVE-2026-20665, CVE-2026-20676, CVE-2026-20691, CVE-2026-28857,
      CVE-2026-28859, CVE-2026-28861, CVE-2026-28871
  * Added some patches from Debian's 2.52.3-2 package (Thanks to Alberto
    Garcia):
    - fix-atomics-detection.patch: Improve detection of whether libatomic
      is required. This was failing in some architectures (armhf, armel)
      with some versions of clang.
    - fix-big-endian-string.patch: Use the native byte order when
      converting from utf8 to utf16. This fixes strings in big-endian
      machine.

 -- Marc Deslauriers <email address hidden> Thu, 23 Apr 2026 08:35:09 -0400

Source diff to previous version
CVE-2025-43213 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, v
CVE-2025-43214 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, v
CVE-2025-43457 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1,
CVE-2025-43511 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.2 and
CVE-2025-46299 A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe
CVE-2026-20608 This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.
CVE-2026-20635 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, ma
CVE-2026-20636 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3.
CVE-2026-20643 A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for
CVE-2026-20644 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, ma
CVE-2026-20652 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, ma
CVE-2026-20664 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4.
CVE-2026-20665 This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.
CVE-2026-20676 This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS
CVE-2026-20691 An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4,
CVE-2026-28857 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4.
CVE-2026-28859 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, vis
CVE-2026-28861 A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.
CVE-2026-28871 A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS T

Version: 2.50.4-0ubuntu0.24.04.1 2026-01-13 18:07:48 UTC

  webkit2gtk (2.50.4-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.50.4 to fix security issues.
    - CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531,
      CVE-2025-43535, CVE-2025-43536, CVE-2025-43541

 -- Marc Deslauriers <email address hidden> Tue, 06 Jan 2026 08:15:42 -0500

Source diff to previous version
CVE-2025-14174 Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access
CVE-2025-43501 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and i
CVE-2025-43529 A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3,
CVE-2025-43531 A race condition was addressed with improved state handling. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2
CVE-2025-43535 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, ma
CVE-2025-43536 A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Tahoe 26.2, iOS 26.2 and iPadOS 26.2, Safari 26.2,
CVE-2025-43541 A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPa

Version: 2.50.3-0ubuntu0.24.04.1 2026-01-05 16:10:33 UTC

  webkit2gtk (2.50.3-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.50.3 to fix security issues.
    - Dropped patches no longer needed:
      + debian/patches/fix-link-error.patch
      + debian/patches/fix-crash.patch
    - CVE-2025-13947
    - CVE-2025-43421
    - CVE-2025-43458
    - CVE-2025-66287

 -- Marc Deslauriers <email address hidden> Tue, 09 Dec 2025 08:38:09 -0500

Source diff to previous version
CVE-2025-13947 A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted
CVE-2025-43421 Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.
CVE-2025-43458 This issue was addressed through improved state management. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.
CVE-2025-66287 A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

Version: 2.50.2-0ubuntu0.24.04.2 2025-12-09 20:10:25 UTC

  webkit2gtk (2.50.2-0ubuntu0.24.04.2) noble-security; urgency=medium

  * Update to 2.50.2 to fix security issues.
    - Add patches from resolute package:
      + debian/patches/fix-link-error.patch:
      + debian/patches/fix-crash.patch:
    - CVE-2025-43392, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429,
      CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434,
      CVE-2025-43440, CVE-2025-43443

 -- Marc Deslauriers <email address hidden> Mon, 01 Dec 2025 07:32:52 -0500

CVE-2025-43392 The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. A website may exfiltrate image data cr
CVE-2025-43425 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvO
CVE-2025-43427 This issue was addressed through improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, tvOS 26.1, Safari 26.1, visionOS 26.1. P
CVE-2025-43429 A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted we
CVE-2025-43430 This issue was addressed through improved state management. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1
CVE-2025-43431 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web conten
CVE-2025-43432 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and i
CVE-2025-43434 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously cra
CVE-2025-43440 This issue was addressed with improved checks This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. P
CVE-2025-43443 This issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web content may le



About   -   Send Feedback to @ubuntu_updates