INFSA-2025:13782: webkit2gtk3 security update

Information about definition

Identificator: INFSA-2025:13782

Type: security

Release date: 2025-08-19 21:44:13 UTC

Information about package

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Vulnerabilities description

  • CVE-2025-31273

    A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

  • CVE-2025-31278

    A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling

  • CVE-2025-43211

    A flaw was found in WebKitGTK. Processing malicious web content can cause a denial of service due to improper memory handling.

  • CVE-2025-43212

    A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

  • CVE-2025-43216

    A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory management and result in an unexpected process crash.

  • CVE-2025-43227

    A flaw was found in WebKitGTK. Processing malicious web content can disclose sensitive user information due to improper state management.

  • CVE-2025-43240

    A flaw was found in WebKitGTK. A malicious website can cause the origin of a download to be incorrectly associated with the wrong site due to improper checks, allowing an attacker to trick a user into downloading a malicious file.

  • CVE-2025-43265

    A flaw was found in WebKitGTK. Processing malicious web content can trigger an out-of-bounds read due to improper input validation, resulting in the disclosure of the internal states of the application.

  • CVE-2025-6558

    A flaw was found in the libANGLE library. An improper input validation can cause undefined behavior when a specially crafted webpage is visited, potentially resulting in code execution.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 8.8 no information
no information 8.8 no information
no information 6.5 no information
no information 8.8 no information
no information 8.8 no information
no information 6.5 no information
no information 6.5 no information
no information 6.5 no information
NIST — CVE-2025-6558
no information 8.8 no information
Critical, important, moderate, low

Updated packages