Amazon Linux 2 : webkitgtk4 (ALAS-2026-3917)

high Nessus Plugin ID 345783

概要

遠端 Amazon Linux 2 主機缺少安全性更新。

說明

遠端主機上安裝的 webkitgtk4 版本比 2.52.6-1 舊。因此,會受到 ALAS2-2026-3917 公告中所提及的多個弱點影響。

已透過改進記憶體管理解決釋放後使用問題。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能導致處理程序意外損毀。(CVE-2026-64715)

已透過改進鎖定解決記憶體損毀弱點。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-64779)。

已透過改進檢查解決此問題。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-64780)。

已透過改進邊界檢查解決超出邊界存取問題。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-64784)。

此問題已透過改進狀態管理解決。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-65331)。

此問題已透過改進狀態管理解決。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-65333)。

已透過改進狀態管理解決記憶體損毀問題。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-65334)。

此問題已透過改進狀態管理解決。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-65335)。

此問題已透過改進狀態管理解決。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-65336)。

此問題已透過改進狀態管理解決。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-65337)。

已透過改進記憶體處理解決此問題。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-65338)。

此問題已透過改進狀態管理解決。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能會導致 Safari 意外當機 (CVE-2026-65340)。

已透過改進記憶體處理解決此問題。已在 Safari 26.6.1、iOS 18.7.10 和 iPadOS 18.7.10、iOS 26.6.1 和 iPadOS 26.6.1、macOS Tahoe 26.6.2 中修復此問題。處理惡意特製的 Web 內容可能導致記憶體損毀。(CVE-2026-65341)

在 WebKitGTK 中發現缺陷。處理惡意 Web 內容可能會因記憶體處理不當而導致釋放後使用問題,並導致記憶體損毀。(CVE-2026-78376)

在 WebKitGTK 中發現缺陷。處理惡意 Web 內容可能會因記憶體處理不當而導致記憶體損毀。(CVE-2026-83596)

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「yum update webkitgtk4」或「yum update --advisory ALAS2-2026-3917」以更新系統。

另請參閱

https://alas.aws.amazon.com//AL2/ALAS2-2026-3917.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-64715.html

https://explore.alas.aws.amazon.com/CVE-2026-64779.html

https://explore.alas.aws.amazon.com/CVE-2026-64780.html

https://explore.alas.aws.amazon.com/CVE-2026-64784.html

https://explore.alas.aws.amazon.com/CVE-2026-65331.html

https://explore.alas.aws.amazon.com/CVE-2026-65333.html

https://explore.alas.aws.amazon.com/CVE-2026-65334.html

https://explore.alas.aws.amazon.com/CVE-2026-65335.html

https://explore.alas.aws.amazon.com/CVE-2026-65336.html

https://explore.alas.aws.amazon.com/CVE-2026-65337.html

https://explore.alas.aws.amazon.com/CVE-2026-65338.html

https://explore.alas.aws.amazon.com/CVE-2026-65340.html

https://explore.alas.aws.amazon.com/CVE-2026-65341.html

https://explore.alas.aws.amazon.com/CVE-2026-78376.html

https://explore.alas.aws.amazon.com/CVE-2026-83596.html

Plugin 詳細資訊

嚴重性: High

ID: 345783

檔案名稱: al2_ALAS-2026-3917.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/9/14

已更新: 2026/9/14

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 4.9

百分位數: 58.18

CVSS v2

風險因素: Critical

基本分數: 10

時間性分數: 7.4

媒介: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS 評分資料來源: CVE-2026-83596

CVSS v3

風險因素: High

基本分數: 8.8

時間性分數: 7.7

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

弱點資訊

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:webkitgtk4-devel, p-cpe:/a:amazon:linux:webkitgtk4-jsc-devel, p-cpe:/a:amazon:linux:webkitgtk4-jsc, p-cpe:/a:amazon:linux:webkitgtk4

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2026/9/14

弱點發布日期: 2026/8/17

參考資訊

CVE: CVE-2026-64715, CVE-2026-64779, CVE-2026-64780, CVE-2026-64784, CVE-2026-65331, CVE-2026-65333, CVE-2026-65334, CVE-2026-65335, CVE-2026-65336, CVE-2026-65337, CVE-2026-65338, CVE-2026-65340, CVE-2026-65341, CVE-2026-78376, CVE-2026-83596