Amazon Linux 2:webkitgtk4、--advisory ALAS2-2026-3843 (ALAS-2026-3843)

high Nessus 插件 ID 332028

简介

远程 Amazon Linux 2 主机缺少安全更新。

描述

远程主机上安装的 webkitgtk4 版本低于 2.52.5-1。因此,该软件受到 ALAS2-2026-3843 公告中提及的多个漏洞影响。

在 xdgmime 中发现一个缺陷。在小端系统上,当攻击者控制的位于用户可写入 XDG 数据位置
(例如,在 $XDG_DATA_HOME/mime/magic 路径中)的 MIME 魔术文件被执行 MIME 类型检测的应用程序(例如,通过 g_content_type_guess())解析时,xdgmimemagic.c 文件中的 _xdg_mime_magic_parse_magic_line() 函数可能会触发基于堆的缓冲区溢出。执行字节交换时,写入端的错误指针算术运算会造成 2 字节的越界写入,从而导致应用程序崩溃或内存损坏。(CVE-2026-16118)

已通过改进内存处理解决此问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容或可导致进程意外崩溃。(CVE-2026-39872)

已通过改进内存处理解决此问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容或可导致进程意外崩溃。(CVE-2026-43663)

已通过改进边界检查解决越界访问权限问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致 Safari 意外崩溃。(CVE-2026-43676)

已通过改进内存管理解决释放后使用问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容或可导致进程意外崩溃。(CVE-2026-43699)

已通过改进检查解决此问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。恶意网站可能会在沙盒之外处理受限制的 Web 内容。(CVE-2026-43701)

已通过改进的检查处理解决类型混淆问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致内存损坏。(CVE-2026-43705)

已通过改进的内存处理解决内存损坏问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容或可导致进程意外崩溃。(CVE-2026-43707)

已通过改进内存处理解决此问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容或可导致进程意外崩溃。(CVE-2026-43712)

已通过额外限制解决此权限问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。访问网站可能会泄露敏感数据 (CVE-2026-43713)

已通过改进内存管理解决释放后使用问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致内存损坏。(CVE-2026-43715)

已通过改进内存处理解决此问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致 Safari 意外崩溃。(CVE-2026-43716)

已通过改进内存管理解决释放后使用问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致 Safari 意外崩溃。(CVE-2026-43720)

已通过改进输入验证解决此问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。恶意网站可能会在沙盒之外处理受限制的 Web 内容。(CVE-2026-43725)

已通过改进内存管理解决释放后使用问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容或可导致进程意外崩溃。(CVE-2026-43726)

已通过改进内存管理解决释放后使用问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致 Safari 意外崩溃。(CVE-2026-43727)

已通过改进内存管理解决释放后使用问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致内存损坏。(CVE-2026-43731)

已通过改进的验证解决路径处理问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能会泄露敏感用户信息。(CVE-2026-43732)

已通过改进内存管理解决释放后使用问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容或可导致进程意外崩溃。(CVE-2026-43734)

已通过改进内存处理解决此问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致进程内存泄漏。(CVE-2026-43740)

已通过改进内存管理解决释放后使用问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容或可导致进程意外崩溃。(CVE-2026-43742)

已通过改进输入验证解决越界写入问题。已在 Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2 中修复此问题。处理恶意构建的 Web 内容可能导致 Safari 意外崩溃。(CVE-2026-43745)

Tenable 已直接从测试产品的安全公告中提取上述描述块。

请注意,Nessus 尚未测试这些问题,而是只依据应用程序自我报告的版本号进行判断。

解决方案

运行“yum update webkitgtk4”或“yum update --advisory ALAS2-2026-3843”以更新系统。

另见

https://alas.aws.amazon.com//AL2/ALAS2-2026-3843.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-16118.html

https://explore.alas.aws.amazon.com/CVE-2026-39872.html

https://explore.alas.aws.amazon.com/CVE-2026-43663.html

https://explore.alas.aws.amazon.com/CVE-2026-43676.html

https://explore.alas.aws.amazon.com/CVE-2026-43699.html

https://explore.alas.aws.amazon.com/CVE-2026-43701.html

https://explore.alas.aws.amazon.com/CVE-2026-43705.html

https://explore.alas.aws.amazon.com/CVE-2026-43707.html

https://explore.alas.aws.amazon.com/CVE-2026-43712.html

https://explore.alas.aws.amazon.com/CVE-2026-43713.html

https://explore.alas.aws.amazon.com/CVE-2026-43715.html

https://explore.alas.aws.amazon.com/CVE-2026-43716.html

https://explore.alas.aws.amazon.com/CVE-2026-43720.html

https://explore.alas.aws.amazon.com/CVE-2026-43725.html

https://explore.alas.aws.amazon.com/CVE-2026-43726.html

https://explore.alas.aws.amazon.com/CVE-2026-43727.html

https://explore.alas.aws.amazon.com/CVE-2026-43731.html

https://explore.alas.aws.amazon.com/CVE-2026-43732.html

https://explore.alas.aws.amazon.com/CVE-2026-43734.html

https://explore.alas.aws.amazon.com/CVE-2026-43740.html

https://explore.alas.aws.amazon.com/CVE-2026-43742.html

https://explore.alas.aws.amazon.com/CVE-2026-43745.html

插件详情

严重性: High

ID: 332028

文件名: al2_ALAS-2026-3843.nasl

版本: 1.1

类型: Local

代理: unix

发布时间: 2026/8/4

最近更新时间: 2026/8/4

支持的传感器: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

风险信息

VPR

风险因素: Medium

分数: 4.9

百分位: 58.12

CVSS v2

风险因素: Critical

基本分数: 10

时间分数: 7.4

矢量: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 分数来源: CVE-2026-43731

CVSS v3

风险因素: High

基本分数: 8.8

时间分数: 7.7

矢量: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

时间矢量: CVSS:3.0/E:U/RL:O/RC:C

漏洞信息

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:webkitgtk4-devel, p-cpe:/a:amazon:linux:webkitgtk4-jsc-devel, p-cpe:/a:amazon:linux:webkitgtk4-jsc, p-cpe:/a:amazon:linux:webkitgtk4

必需的 KB 项: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

易利用性: No known exploits are available

补丁发布日期: 2026/8/4

漏洞发布日期: 2026/6/29

参考资料信息

CVE: CVE-2026-16118, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745