Gnoppix Security Announcement - 2026-08-24T15:49:44.261-04:00

GSA-6463-1: WebKitGTK Security Update

A critical vulnerability in WebKitGTK allows remote code execution via crafted web content on Gnoppix systems. Gnoppix 24/25 and Gnoppix 26 require an urgent patch to block the flaw, which an attacker can trigger without special login rights.

Affected Versions

  • Gnoppix 24/25 (oldstable): vulnerable prior to the new release.
  • Gnoppix 26 (stable): vulnerable prior to the new release.
  • Gnoppix 27 (testing): no update required.

Impact Overview

The WebKitGTK engine mishandles memory page boundaries, allowing remote attackers to crash processes or execute system code. Full system takeover is possible if a malicious page is opened.

Recommended Action

Update the webkit2gtk package immediately to the latest release. After installation, restart all running web services or applications to enforce the fix.

Additional Details

The security update is part of the Gnoppix Security announcement series and supersedes prior DSA notices for the same component. System administrators should verify package versions and deploy the corrected library across all local clients. - Please update your systems.