Several security issues were fixed in WebKitGTK.. ========================================================================== Ubuntu Security Notice USN-7702-1 August 19, 2025 webkit2gtk vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in WebKitGTK. Software Description: - webkit2gtk: Web content engine library for GTK+ Details: Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libjavascriptcoregtk-4.1-0 2.48.5-0ubuntu0.25.04.1 libjavascriptcoregtk-6.0-1 2.48.5-0ubuntu0.25.04.1 libwebkit2gtk-4.1-0 2.48.5-0ubuntu0.25.04.1 libwebkitgtk-6.0-4 2.48.5-0ubuntu0.25.04.1 Ubuntu 24.04 LTS libjavascriptcoregtk-4.1-0 2.48.5-0ubuntu0.24.04.1 libjavascriptcoregtk-6.0-1 2.48.5-0ubuntu0.24.04.1 libwebkit2gtk-4.1-0 2.48.5-0ubuntu0.24.04.1 libwebkitgtk-6.0-4 2.48.5-0ubuntu0.24.04.1 Ubuntu 22.04 LTS libjavascriptcoregtk-4.0-18 2.48.5-0ubuntu0.22.04.1 libjavascriptcoregtk-4.1-0 2.48.5-0ubuntu0.22.04.1 libjavascriptcoregtk-6.0-1 2.48.5-0ubuntu0.22.04.1 libwebkit2gtk-4.0-37 2.48.5-0ubuntu0.22.04.1 libwebkit2gtk-4.1-0 2.48.5-0ubuntu0.22.04.1 libwebkitgtk-6.0-4 2.48.5-0ubuntu0.22.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any applications that use WebKitGTK, such as Epiphany, to make all thenecessary changes. References: https://ubuntu.com/security/notices/USN-7702-1 CVE-2025-31273, CVE-2025-31278, CVE-2025-43211, CVE-2025-43212, CVE-2025-43216, CVE-2025-43227, CVE-2025-43228, CVE-2025-43240, CVE-2025-43265, CVE-2025-6558 Package Information: https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.5-0ubuntu0.25.04.1 https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.5-0ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/webkit2gtk/2.48.5-0ubuntu0.22.04.1 . Significant vulnerabilities addressed in WebKitGTK for Ubuntu, posing threats including potential remote code execution and service interruptions.. WebKitGTK security, Ubuntu vulnerabilities, remote execution risk. . Severity: Important. LinuxSecurity.com Team
Type confusion leading to arbitrary code execution using crafted web page (CVE-2023-23529) References: - https://bugs.mageia.org/show_bug.cgi?id=31555 . MGASA-2023-0055 - Updated webkit2 packages fix security vulnerability Publication date: 20 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0055.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-23529 Type confusion leading to arbitrary code execution using crafted web page (CVE-2023-23529) References: - https://bugs.mageia.org/show_bug.cgi?id=31555 - https://webkitgtk.org/security/WSA-2023-0002.html - https://webkitgtk.org/2023/02/15/webkitgtk2.38.5-released.html - https://access.redhat.com/security/cve/CVE-2023-23529 - https://www.cve.org/CVERecord?id=CVE-2023-23529 SRPMS: - 8/core/webkit2-2.38.5-1.mga8 . MGASA-2023-0056 enhances appsecurity to mitigate severe data breach vulnerabilities from malicious inputs.. Mageia Security Update, Webkit2 Threat, Code Execution Risk. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202003-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: WebkitGTK+: Multiple vulnerabilities Date: March 15, 2020 Bugs: #699156, #706374, #709612 ID: 202003-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may lead to arbitrary code execution. Background ========= WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/webkit-gtk < 2.26.4 > = 2.26.4 Description ========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the referenced CVE identifiers for details. Impact ===== A remote attacker could execute arbitrary code, cause a Denial of Service condition, bypass intended memory-read restrictions, conduct a timing side-channel attack to bypass the Same Origin Policy or obtain sensitive information. Workaround ========= There is no known workaround at this time. Resolution ========= All WebkitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/webkit-gtk-2.26.4" References ========= [ 1 ] CVE-2019-8625 https://nvd.nist.gov/vuln/detail/CVE-2019-8625 [ 2 ] CVE-2019-8674 https://nvd.nist.gov/vuln/detail/CVE-2019-8674 [ 3 ] CVE-2019-8707 https://nvd.nist.gov/vuln/detail/CVE-2019-8707 [ 4 ] CVE-2019-8710 https://nvd.nist.gov/vuln/detail/CVE-2019-8710 [ 5 ] CVE-2019-8719 https://nvd.nist.gov/vuln/detail/CVE-2019-8719 [ 6 ] CVE-2019-8720 https://nvd.nist.gov/vuln/detail/CVE-2019-8720 [ 7 ] CVE-2019-8726 https://nvd.nist.gov/vuln/detail/CVE-2019-8726 [ 8 ] CVE-2019-8733 https://nvd.nist.gov/vuln/detail/CVE-2019-8733 [ 9 ] CVE-2019-8735 https://nvd.nist.gov/vuln/detail/CVE-2019-8735 [ 10 ] CVE-2019-8743 https://nvd.nist.gov/vuln/detail/CVE-2019-8743 [ 11 ] CVE-2019-8763 https://nvd.nist.gov/vuln/detail/CVE-2019-8763 [ 12 ] CVE-2019-8764 https://nvd.nist.gov/vuln/detail/CVE-2019-8764 [ 13 ] CVE-2019-8765 https://nvd.nist.gov/vuln/detail/CVE-2019-8765 [ 14 ] CVE-2019-8766 https://nvd.nist.gov/vuln/detail/CVE-2019-8766 [ 15 ] CVE-2019-8768 https://nvd.nist.gov/vuln/detail/CVE-2019-8768 [ 16 ] CVE-2019-8769 https://nvd.nist.gov/vuln/detail/CVE-2019-8769 [ 17 ] CVE-2019-8771 https://nvd.nist.gov/vuln/detail/CVE-2019-8771 [ 18 ] CVE-2019-8782 https://nvd.nist.gov/vuln/detail/CVE-2019-8782 [ 19 ] CVE-2019-8783 https://nvd.nist.gov/vuln/detail/CVE-2019-8783 [ 20 ] CVE-2019-8808 https://nvd.nist.gov/vuln/detail/CVE-2019-8808 [ 21 ] CVE-2019-8811 https://nvd.nist.gov/vuln/detail/CVE-2019-8811 [ 22 ] CVE-2019-8812 https://nvd.nist.gov/vuln/detail/CVE-2019-8812 [ 23 ] CVE-2019-8813 https://nvd.nist.gov/vuln/detail/CVE-2019-8813 [ 24 ] CVE-2019-8814 https://nvd.nist.gov/vuln/detail/CVE-2019-8814 [ 25 ] CVE-2019-8815 https://nvd.nist.gov/vuln/detail/CVE-2019-8815 [ 26 ] CVE-2019-8816 https://nvd.nist.gov/vuln/detail/CVE-2019-8816 [ 27 ] CVE-2019-8819 https://nvd.nist.gov/vuln/detail/CVE-2019-8819 [ 28 ] CVE-2019-8820 https://nvd.nist.gov/vuln/detail/CVE-2019-8820 [ 29 ] CVE-2019-8821 https://nvd.nist.gov/vuln/detail/CVE-2019-8821 [ 30 ] CVE-2019-8822 https://nvd.nist.gov/vuln/detail/CVE-2019-8822 [ 31 ] CVE-2019-8823 https://nvd.nist.gov/vuln/detail/CVE-2019-8823 [ 32 ] CVE-2019-8835 https://nvd.nist.gov/vuln/detail/CVE-2019-8835 [ 33 ] CVE-2019-8844 https://nvd.nist.gov/vuln/detail/CVE-2019-8844 [ 34 ] CVE-2019-8846 https://nvd.nist.gov/vuln/detail/CVE-2019-8846 [ 35 ] CVE-2020-3862 https://nvd.nist.gov/vuln/detail/CVE-2020-3862 [ 36 ] CVE-2020-3864 https://nvd.nist.gov/vuln/detail/CVE-2020-3864 [ 37 ] CVE-2020-3865 https://nvd.nist.gov/vuln/detail/CVE-2020-3865 [ 38 ] CVE-2020-3867 https://nvd.nist.gov/vuln/detail/CVE-2020-3867 [ 39 ] CVE-2020-3868 https://nvd.nist.gov/vuln/detail/CVE-2020-3868 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202003-22 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.