Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 24.10: USN-7436-1 critical: WebKitGTK remote attack risk

Ubuntu Large Esm H500
Several security issues were fixed in WebKitGTK.
==========================================================================
Ubuntu Security Notice USN-7436-1
April 14, 2025

webkit2gtk vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in WebKitGTK.

Software Description:
- webkit2gtk: Web content engine library for GTK+

Details:

Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
   libjavascriptcoregtk-4.1-0      2.48.1-0ubuntu0.24.10.1
   libjavascriptcoregtk-6.0-1      2.48.1-0ubuntu0.24.10.1
   libwebkit2gtk-4.1-0             2.48.1-0ubuntu0.24.10.1
   libwebkitgtk-6.0-4              2.48.1-0ubuntu0.24.10.1

Ubuntu 24.04 LTS
   libjavascriptcoregtk-4.1-0      2.48.1-0ubuntu0.24.04.1
   libjavascriptcoregtk-6.0-1      2.48.1-0ubuntu0.24.04.1
   libwebkit2gtk-4.1-0             2.48.1-0ubuntu0.24.04.1
   libwebkitgtk-6.0-4              2.48.1-0ubuntu0.24.04.1

Ubuntu 22.04 LTS
   libjavascriptcoregtk-4.0-18     2.48.1-0ubuntu0.22.04.1
   libjavascriptcoregtk-4.1-0      2.48.1-0ubuntu0.22.04.1
   libjavascriptcoregtk-6.0-1      2.48.1-0ubuntu0.22.04.1
   libwebkit2gtk-4.0-37            2.48.1-0ubuntu0.22.04.1
   libwebkit2gtk-4.1-0             2.48.1-0ubuntu0.22.04.1
   libwebkitgtk-6.0-4              2.48.1-0ubuntu0.22.04.1

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-7436-1
   CVE-2024-54551, CVE-2025-24208, CVE-2025-24209, CVE-2025-24213,
   CVE-2025-24216, CVE-2025-24264, CVE-2025-30427

Package Information:
   https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.1-0ubuntu0.24.10.1
   https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.1-0ubuntu0.24.04.1
   https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.1-0ubuntu0.22.04.1

Ubuntu 24.10: USN-7436-1 critical: WebKitGTK remote attack risk

ubuntu
Calendar Grey April 14, 2025
Dist Ubuntu Esm H88
Multiple bugs resolved in WebKitGTK throughout Ubuntu versions. Significant upgrade for security improvements and safeguarding users.
Several security issues were fixed in WebKitGTK.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in WebKitGTK. Software Description: - webkit2gtk: Web content engine library for GTK+ Details: Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libjavascriptcoregtk-4.1-0 2.48.1-0ubuntu0.24.10.1 libjavascriptcoregtk-6.0-1 2.48.1-0ubuntu0.24.10.1 libwebkit2gtk-4.1-0 2.48.1-0ubuntu0.24.10.1 libwebkitgtk-6.0-4 2.48.1-0ubuntu0.24.10.1 Ubuntu 24.04 LTS libjavascriptcoregtk-4.1-0 2.48.1-0ubuntu0.24.04.1 libjavascriptcoregtk-6.0-1 2.48.1-0ubuntu0.24.04.1 libwebkit2gtk-4.1-0 2.48.1-0ubuntu0.24.04.1 libwebkitgtk-6.0-4 2.48.1-0ubuntu0.24.04.1 Ubuntu 22.04 LTS libjavascriptcoregtk-4.0-18 2.48.1-0ubuntu0.22.04.1 libjavascriptcoregtk-4.1-0 2.48.1-0ubuntu0.22.04.1 libjavascriptcoregtk-6.0-1 2.48.1-0ubuntu0.22.04.1 libwebkit2gtk-4.0-37 2.48.1-0ubuntu0.22.04.1 libwebkit2gtk-4.1-0 2.48.1-0ubuntu0.22.04.1 libwebkitgtk-6.0-4 2.48.1-0ubuntu0.22.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any applications that use WebKitGTK, such as Epiphany, to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7436-1

CVE-2024-54551, CVE-2025-24208, CVE-2025-24209, CVE-2025-24213,

CVE-2025-24216, CVE-2025-24264, CVE-2025-30427

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7436-1

Package Information

https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.1-0ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.1-0ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.1-0ubuntu0.22.04.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here