INFSA-2025:13782: webkit2gtk3 security update
Information about definition
Identificator: INFSA-2025:13782
Type: security
Release date: 2025-08-19 21:44:13 UTC
Information about package
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.
Vulnerabilities description
- CVE-2025-31273
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
- CVE-2025-31278
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling
- CVE-2025-43211
A flaw was found in WebKitGTK. Processing malicious web content can cause a denial of service due to improper memory handling.
- CVE-2025-43212
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
- CVE-2025-43216
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory management and result in an unexpected process crash.
- CVE-2025-43227
A flaw was found in WebKitGTK. Processing malicious web content can disclose sensitive user information due to improper state management.
- CVE-2025-43240
A flaw was found in WebKitGTK. A malicious website can cause the origin of a download to be incorrectly associated with the wrong site due to improper checks, allowing an attacker to trick a user into downloading a malicious file.
- CVE-2025-43265
A flaw was found in WebKitGTK. Processing malicious web content can trigger an out-of-bounds read due to improper input validation, resulting in the disclosure of the internal states of the application.
- CVE-2025-6558
A flaw was found in the libANGLE library. An improper input validation can cause undefined behavior when a specially crafted webpage is visited, potentially resulting in code execution.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2025-31273
|
no information | 8.8 | no information |
NIST — CVE-2025-31278
|
no information | 8.8 | no information |
NIST — CVE-2025-43211
|
no information | 6.5 | no information |
NIST — CVE-2025-43212
|
no information | 8.8 | no information |
NIST — CVE-2025-43216
|
no information | 8.8 | no information |
NIST — CVE-2025-43227
|
no information | 6.5 | no information |
NIST — CVE-2025-43240
|
no information | 6.5 | no information |
NIST — CVE-2025-43265
|
no information | 6.5 | no information |
NIST — CVE-2025-6558
|
no information | 8.8 | no information |
Updated packages