Debian dsa-6398 : gir1.2-javascriptcoregtk-4.1 - security update

high Nessus Plugin ID 329249

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6398 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6398-1 [email protected] https://www.debian.org/security/ Alberto Garcia July 23, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : webkit2gtk CVE ID : CVE-2024-4367 CVE-2026-28847 CVE-2026-28883 CVE-2026-28901 CVE-2026-28902 CVE-2026-28903 CVE-2026-28904 CVE-2026-28905 CVE-2026-28907 CVE-2026-28942 CVE-2026-28946 CVE-2026-28947 CVE-2026-28953 CVE-2026-28955 CVE-2026-28958 CVE-2026-39872 CVE-2026-43658 CVE-2026-43660 CVE-2026-43663 CVE-2026-43676 CVE-2026-43699 CVE-2026-43701 CVE-2026-43705 CVE-2026-43707 CVE-2026-43712 CVE-2026-43713 CVE-2026-43715 CVE-2026-43716 CVE-2026-43720 CVE-2026-43721 CVE-2026-43725 CVE-2026-43726 CVE-2026-43727 CVE-2026-43731 CVE-2026-43732 CVE-2026-43734 CVE-2026-43740 CVE-2026-43742 CVE-2026-43745

The following vulnerabilities have been discovered in the WebKitGTK web engine:

CVE-2024-4367

Thomas Rinsma discovered that a type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.

CVE-2026-28847

DARKNAVY, an anonymous researcher and Daniel Rhea discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28883

Kwak Kiyong discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28901

Joshua Rogers, Luigino Camastra, Igor Morgenstern, Guido Vranken, Maher Azzouzi and Ngan Nguyen discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28902

Tristan Madani and Nathaniel Oh discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28903

Mateusz Krzywicki discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28904

Luka Racki discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28905

Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28907

Cantina discovered that processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVE-2026-28942

Milad Nasr and Nicholas Carlini discovered that processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2026-28946

Gia Bui, dr3dd, and w0wbox discovered that processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2026-28947

dr3dd discovered that processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2026-28953

Maher Azzouzi discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28955

wac and Kookhwan Lee discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-28958

Cantina discovered that an app may be able to access sensitive user data.

CVE-2026-39872

Utkarsh Pal and Ignacio Sanmillan discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43658

Do Young Park discovered that processing maliciously crafted web content may lead to an unexpected Safari crash.

CVE-2026-43660

Cantina discovered that processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVE-2026-43663

Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda, HexRabbit, NiNi, Tristan Madani and Brian Carpenter discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43676

Mateusz Krzywicki, dr3dd, and Tommy DeVoss discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43699

Tommy DeVoss discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43701

Aaron Grattafiori discovered that a malicious website may be able to process restricted web content outside the sandbox.

CVE-2026-43705

dr3dd discovered that processing maliciously crafted web content may lead to memory corruption.

CVE-2026-43707

Amy Burnett discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43712

Kwak Kiyong, Song Nuri, and Tristan Madani discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43713

Jody Ritonga discovered that visiting a website may leak sensitive data.

CVE-2026-43715

Milad Nasr and Nicholas Carlini discovered that processing maliciously crafted web content may lead to memory corruption.

CVE-2026-43716

Tuan, Duc, Amy Burnett and Evan Lambert discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43720

Gia Bui and Josef Korbel discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43721

Idan Masas discovered that a malicious website may be able to silently hijack clipboard data.

CVE-2026-43725

Luke Francis discovered that a malicious website may be able to process restricted web content outside the sandbox.

CVE-2026-43726

Josef Korbel, Tristan Madani, Gia Bui and Narendra Singh discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43727

Tommy DeVoss, Gia Bui and Gurpreet Shergill discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43731

dr3dd discovered that processing maliciously crafted web content may lead to memory corruption.

CVE-2026-43732

Nan Wang discovered that processing maliciously crafted web content may disclose sensitive user information.

CVE-2026-43734

Jonathan Alush-Aben discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43740

Nathaniel Oh and Arni Hardarson discovered that processing maliciously crafted web content may result in the disclosure of process memory.

CVE-2026-43742

Yulia Mertsalova discovered that processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2026-43745

Amy Burnett and Khai Tran discovered that processing maliciously crafted web content may lead to an unexpected process crash.

For the stable distribution (trixie), these problems have been fixed in version 2.52.5-1~deb13u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/webkit2gtk

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the gir1.2-javascriptcoregtk-4.1 packages.

See Also

https://packages.debian.org/source/trixie/webkit2gtk

https://security-tracker.debian.org/tracker/CVE-2024-4367

https://security-tracker.debian.org/tracker/CVE-2026-28847

https://security-tracker.debian.org/tracker/CVE-2026-28883

https://security-tracker.debian.org/tracker/CVE-2026-28901

https://security-tracker.debian.org/tracker/CVE-2026-28902

https://security-tracker.debian.org/tracker/CVE-2026-28903

https://security-tracker.debian.org/tracker/CVE-2026-28904

https://security-tracker.debian.org/tracker/CVE-2026-28905

https://security-tracker.debian.org/tracker/CVE-2026-28907

https://security-tracker.debian.org/tracker/CVE-2026-28942

https://security-tracker.debian.org/tracker/CVE-2026-28946

https://security-tracker.debian.org/tracker/CVE-2026-28947

https://security-tracker.debian.org/tracker/CVE-2026-28953

https://security-tracker.debian.org/tracker/CVE-2026-28955

https://security-tracker.debian.org/tracker/CVE-2026-28958

https://security-tracker.debian.org/tracker/CVE-2026-39872

https://security-tracker.debian.org/tracker/CVE-2026-43658

https://security-tracker.debian.org/tracker/CVE-2026-43660

https://security-tracker.debian.org/tracker/CVE-2026-43663

https://security-tracker.debian.org/tracker/CVE-2026-43676

https://security-tracker.debian.org/tracker/CVE-2026-43699

https://security-tracker.debian.org/tracker/CVE-2026-43701

https://security-tracker.debian.org/tracker/CVE-2026-43705

https://security-tracker.debian.org/tracker/CVE-2026-43707

https://security-tracker.debian.org/tracker/CVE-2026-43712

https://security-tracker.debian.org/tracker/CVE-2026-43713

https://security-tracker.debian.org/tracker/CVE-2026-43715

https://security-tracker.debian.org/tracker/CVE-2026-43716

https://security-tracker.debian.org/tracker/CVE-2026-43720

https://security-tracker.debian.org/tracker/CVE-2026-43721

https://security-tracker.debian.org/tracker/CVE-2026-43725

https://security-tracker.debian.org/tracker/CVE-2026-43726

https://security-tracker.debian.org/tracker/CVE-2026-43727

https://security-tracker.debian.org/tracker/CVE-2026-43731

https://security-tracker.debian.org/tracker/CVE-2026-43732

https://security-tracker.debian.org/tracker/CVE-2026-43734

https://security-tracker.debian.org/tracker/CVE-2026-43740

https://security-tracker.debian.org/tracker/CVE-2026-43742

https://security-tracker.debian.org/tracker/CVE-2026-43745

https://security-tracker.debian.org/tracker/source-package/webkit2gtk

Plugin Details

Severity: High

ID: 329249

File Name: debian_DSA-6398.nasl

Version: 1.2

Type: Local

Agent: unix

Published: 7/23/2026

Updated: 7/24/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.86

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-4367

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:gir1.2-javascriptcoregtk-4.1, p-cpe:/a:debian:debian_linux:gir1.2-javascriptcoregtk-6.0, p-cpe:/a:debian:debian_linux:gir1.2-webkit-6.0, p-cpe:/a:debian:debian_linux:gir1.2-webkit2-4.1, p-cpe:/a:debian:debian_linux:libjavascriptcoregtk-4.0-bin, p-cpe:/a:debian:debian_linux:libjavascriptcoregtk-4.1-0, p-cpe:/a:debian:debian_linux:libjavascriptcoregtk-4.1-dev, p-cpe:/a:debian:debian_linux:libjavascriptcoregtk-6.0-1, p-cpe:/a:debian:debian_linux:libjavascriptcoregtk-6.0-dev, p-cpe:/a:debian:debian_linux:libjavascriptcoregtk-bin, p-cpe:/a:debian:debian_linux:libwebkit2gtk-4.0-doc, p-cpe:/a:debian:debian_linux:libwebkit2gtk-4.1-0, p-cpe:/a:debian:debian_linux:libwebkit2gtk-4.1-dev, p-cpe:/a:debian:debian_linux:libwebkitgtk-6.0-4, p-cpe:/a:debian:debian_linux:libwebkitgtk-6.0-dev, p-cpe:/a:debian:debian_linux:libwebkitgtk-doc, p-cpe:/a:debian:debian_linux:webkit2gtk-driver, p-cpe:/a:debian:debian_linux:webkitgtk-webdriver

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/23/2026

Vulnerability Publication Date: 5/7/2024

Reference Information

CVE: CVE-2024-4367, CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-39872, CVE-2026-43658, CVE-2026-43660, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745