Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian 11: DLA-4218-1 critical: webkit2gtk multiple process crashes

debian lts
Calendar Grey June 16, 2025
Dist Debian Esm H88
Enhance webkit2gtk within the Debian LTS framework to mitigate various significant security vulnerabilities associated with the handling of web content.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-44192

Summary

CVE-2024-44192

Tashita Software Security discovered that processing maliciously
crafted web content may lead to an unexpected process crash.

CVE-2024-54467

Narendra Bhati discovered that a malicious website may exfiltrate
data cross-origin.

CVE-2024-54551

ajajfxhj discovered that processing web content may lead to a
denial-of-service.

CVE-2025-24201

Apple discovered that maliciously crafted web content may be able
to break out of Web Content sandbox.

CVE-2025-24208

Muhammad Zaid Ghifari and Kalimantan Utara discovered that loading
a malicious iframe may lead to a cross-site scripting attack.

CVE-2025-24209

Francisco Alonso and an anonymous researcher discovered that
processing maliciously crafted web content may lead to an
unexpected process crash.

CVE-2025-24213

The Google V8 Security Team discovered that a type confusion issue
could lead to memory corruption. Note that this CVE is fixed only

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
Version: 2.48.3-1~deb11u1
CVE ID: CVE-2024-44192 CVE-2024-54467 CVE-2024-54551 CVE-2025-24201

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here