Multiple vulnerabilities have been discovered in WebKitGTK+, the worst of which can lead to execution of arbitary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202511-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: WebKitGTK+: Multiple Vulnerabilities Date: November 24, 2025 Bugs: #938026, #941276, #951739, #961021 ID: 202511-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in WebKitGTK+, the worst of which can lead to execution of arbitary code. Background ========== WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------- net-libs/webkit-gtk < 2.48.5:4.1 > = 2.48.5:4.1 < 2.48.5:6 > = 2.48.5:6 Description =========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All WebKitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/webkit-gtk-2.48.5:4.1" "> =net-libs/webkit-gtk-2.48.5:6" References ========== [ 1 ] CVE-2024-40857 https://nvd.nist.gov/vuln/detail/CVE-2024-40857 [ 2 ] CVE-2024-40866 https://nvd.nist.gov/vuln/detail/CVE-2024-40866 [ 3 ] CVE-2024-44185 https://nvd.nist.gov/vuln/detail/CVE-2024-44185 [ 4 ] CVE-2024-44187 https://nvd.nist.gov/vuln/detail/CVE-2024-44187 [ 5 ] CVE-2024-44192 https://nvd.nist.gov/vuln/detail/CVE-2024-44192 [ 6 ] CVE-2024-44244 https://nvd.nist.gov/vuln/detail/CVE-2024-44244 [ 7 ] CVE-2024-44296 https://nvd.nist.gov/vuln/detail/CVE-2024-44296 [ 8 ] CVE-2024-54467 https://nvd.nist.gov/vuln/detail/CVE-2024-54467 [ 9 ] CVE-2024-54551 https://nvd.nist.gov/vuln/detail/CVE-2024-54551 [ 10 ] CVE-2025-24201 https://nvd.nist.gov/vuln/detail/CVE-2025-24201 [ 11 ] CVE-2025-24208 https://nvd.nist.gov/vuln/detail/CVE-2025-24208 [ 12 ] CVE-2025-24209 https://nvd.nist.gov/vuln/detail/CVE-2025-24209 [ 13 ] CVE-2025-24213 https://nvd.nist.gov/vuln/detail/CVE-2025-24213 [ 14 ] CVE-2025-24216 https://nvd.nist.gov/vuln/detail/CVE-2025-24216 [ 15 ] CVE-2025-24264 https://nvd.nist.gov/vuln/detail/CVE-2025-24264 [ 16 ] CVE-2025-30427 https://nvd.nist.gov/vuln/detail/CVE-2025-30427 [ 17 ] CVE-2025-31273 https://nvd.nist.gov/vuln/detail/CVE-2025-31273 [ 18 ] CVE-2025-31278 https://nvd.nist.gov/vuln/detail/CVE-2025-31278 [ 19 ] CVE-2025-43211 https://nvd.nist.gov/vuln/detail/CVE-2025-43211 [ 20 ] CVE-2025-43212 https://nvd.nist.gov/vuln/detail/CVE-2025-43212 [ 21 ] CVE-2025-43216 https://nvd.nist.gov/vuln/detail/CVE-2025-43216 [ 22 ] CVE-2025-43227 https://nvd.nist.gov/vuln/detail/CVE-2025-43227 [ 23 ] CVE-2025-43228 https://nvd.nist.gov/vuln/detail/CVE-2025-43228 [ 24 ] CVE-2025-43240 https://nvd.nist.gov/vuln/detail/CVE-2025-43240 [ 25 ] CVE-2025-43265 https://nvd.nist.gov/vuln/detail/CVE-2025-43265 [ 26 ] WSA-2025-0002 https://webkitgtk.org/security/WSA-2025-0002.html [ 27 ] WSA-2025-0003 https://webkitgtk.org/security/WSA-2025-0003.html Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202511-02 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: WebKitGTK+: Multiple vulnerabilities Date: July 26, 2020 Bugs: #732104 ID: 202007-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code. Background ========= WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/webkit-gtk < 2.28.3 > = 2.28.3 Description ========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All WebKitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/webkit-gtk-2.28.3" References ========= [ 1 ] CVE-2020-13753 https://nvd.nist.gov/vuln/detail/CVE-2020-13753 [ 2 ] CVE-2020-9802 https://nvd.nist.gov/vuln/detail/CVE-2020-9802 [ 3 ] CVE-2020-9803 https://nvd.nist.gov/vuln/detail/CVE-2020-9803 [ 4 ] CVE-2020-9805 https://nvd.nist.gov/vuln/detail/CVE-2020-9805 [ 5 ] CVE-2020-9806 https://nvd.nist.gov/vuln/detail/CVE-2020-9806 [ 6 ] CVE-2020-9807 https://nvd.nist.gov/vuln/detail/CVE-2020-9807 [ 7 ] CVE-2020-9843 https://nvd.nist.gov/vuln/detail/CVE-2020-9843 [ 8 ] CVE-2020-9850 https://nvd.nist.gov/vuln/detail/CVE-2020-9850 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-11 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.