Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:13780

Опубликовано: 08 сент. 2025
Источник: rocky
Оценка: Important

Описание

Important: webkit2gtk3 security update

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • angle: insufficient input validation can cause undefined behavior (CVE-2025-6558)

  • webkitgtk: A download?s origin may be incorrectly associated (CVE-2025-43240)

  • webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2025-31273)

  • webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2025-31278)

  • webkitgtk: Processing web content may lead to a denial-of-service (CVE-2025-43211)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43212)

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43216)

  • webkitgtk: Processing maliciously crafted web content may disclose sensitive user information (CVE-2025-43227)

  • webkitgtk: Processing maliciously crafted web content may disclose internal states of the app (CVE-2025-43265)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
webkit2gtk3x86_641.el8_10webkit2gtk3-2.48.5-1.el8_10.x86_64.rpm
webkit2gtk3-develx86_641.el8_10webkit2gtk3-devel-2.48.5-1.el8_10.x86_64.rpm
webkit2gtk3-jscx86_641.el8_10webkit2gtk3-jsc-2.48.5-1.el8_10.x86_64.rpm
webkit2gtk3-jsc-develx86_641.el8_10webkit2gtk3-jsc-devel-2.48.5-1.el8_10.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 1 месяца назад

ELSA-2025-13782: webkit2gtk3 security update (IMPORTANT)

oracle-oval
около 1 месяца назад

ELSA-2025-13780: webkit2gtk3 security update (IMPORTANT)

suse-cvrf
24 дня назад

Security update for webkit2gtk3

suse-cvrf
около 1 месяца назад

Security update for webkit2gtk3

suse-cvrf
около 1 месяца назад

Security update for webkit2gtk3