[DSA 5978-1] webkit2gtk security update

Alberto Garcia <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5978-1                   [email protected]
https://www.debian.org/security/                           Alberto Garcia
August 18, 2025                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : webkit2gtk
CVE ID         : CVE-2025-6558 CVE-2025-31273 CVE-2025-31278 CVE-2025-43211
                 CVE-2025-43212 CVE-2025-43216 CVE-2025-43227 CVE-2025-43228
                 CVE-2025-43240 CVE-2025-43265

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2025-6558

    Clement Lecigne and Vlad Stolyarov discovered that processing
    maliciously crafted web content may lead to an unexpected crash.

CVE-2025-31273

    Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei discovered that
    processing maliciously crafted web content may lead to memory
    corruption.

CVE-2025-31278

    Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei discovered that
    processing maliciously crafted web content may lead to memory
    corruption.

CVE-2025-43211

    Yuhao Hu, Yan Kang, Chenggang Wu, and Xiaojie Wei discovered that
    processing web content may lead to a denial-of-service.

CVE-2025-43212

    Nan Wang and Ziling Chen discovered that processing maliciously
    crafted web content may lead to an unexpected crash.

CVE-2025-43216

    Ignacio Sanmillan discovered that processing maliciously crafted
    web content may lead to an unexpected crash.

CVE-2025-43227

    Gilad Moav discovered that processing maliciously crafted web
    content may disclose sensitive user information.

CVE-2025-43228

    Jaydev Ahire discovered that visiting a malicious website may lead
    to address bar spoofing.

CVE-2025-43240

    Syarif Muhammad Sajjad discovered that a download's origin may be
    incorrectly associated.

CVE-2025-43265

    HexRabbit discovered that processing maliciously crafted web
    content may disclose internal states of the app.

For the oldstable distribution (bookworm), these problems have been fixed
in version 2.48.5-1~deb12u1.

For the stable distribution (trixie), these problems have been fixed in
version 2.48.5-1~deb13u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/webkit2gtk

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmijW78ACgkQAAyEYu0C
2AJkCQ//ULjVlgl3+r19RP2AUS5dmymj16Yok9xNISKZKGZfwusnoLUQml0GcT50
Ybu8T2f/lPs1blmUHJXMsuDYXZfEUaWUVmeH2q3VWYP+/we9EjHJj8gpoUtWuG4T
5i9jHLp+9AkYhseGs3NLEcCeASQ+cp1Db4iEM927BkNbup9myhTAom7N6fO8z95J
NE/BQC/iJTzvVJ7FwSHE9CykD8CyN/lj3m3OWvSm/E52lb10cE9o4TZFmTQ7H8jK
lbIwHUF3xcTHbRPbQzWdVmhIvgZfzUxffZKosaFAymmU19a41TZTZqSk+oMHmxdD
5zCO8eAIimNN1H4URZwYFy028Mq9hHZEGX7DjAwcNVfR2bb/mcXsjIzZfBPsacYB
VFywzRtGV1JI9Rz7Ecml0GyUx8u3Wwkw8Dorf77GV1ZxClWDFnPhO5cLDIIE7MkD
dRHtxvB7hGEQDU1g8qR3fzr5KRitt5VDiLtZhsSsp4q2gcIPh5m1hsGXkBirFyUj
XjICUn+GIMOs3bj15vdi2H8lsW0vTSDyxdfmnv0nxmuFCbBUQ/CwFlHLi8JX0v5a
8/4c6Xw7CcxQx7p7QvbKdFCbPhoyU2MTlnKoqlGiCUOyZ7bDtjDBwcAs5NDb8fjE
06KTXVUyfZr5pO140fvGYZ6eHOj4xLpcKkjjCfLjfwW2J15lo8k=
=G9bE
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.