Red Hat Security Advisory: webkit2gtk3 security update
🔗 CVE IDs covered (30)
📋 Description
CVE-2022-32885 — webkitgtk: Memory corruption issue when processing web content CVE-2022-48503 — webkitgtk: improper bounds checking leading to arbitrary code execution CVE-2023-40397 — webkitgtk: arbitrary javascript code execution CVE-2023-42852 — webkitgtk: Processing web content may lead to arbitrary code execution CVE-2023-42875 — webkitgtk: Processing web content may lead to arbitrary code execution CVE-2023-42917 — webkitgtk: Arbitrary Remote Code Execution CVE-2023-42970 — webkitgtk: Processing web content may lead to arbitrary code execution CVE-2023-43000 — webkitgtk: Processing maliciously crafted web content may lead to memory corruption CVE-2023-43010 — webkitgtk: Processing maliciously crafted web content may lead to memory corruption CVE-2024-4558 — chromium-browser: Use after free in ANGLE CVE-2024-23222 — webkitgtk: type confusion may lead to arbitrary code execution CVE-2024-27808 — webkitgtk: Processing web content may lead to arbitrary code execution CVE-2024-27820 — webkitgtk: Processing web content may lead to arbitrary code execution CVE-2024-27833 — webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution CVE-2024-27851 — webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution CVE-2024-27856 — webkitgtk: Processing a file may lead to unexpected app termination or arbitrary code execution CVE-2024-40776 — webkitgtk: webkit2gtk: Use after free may lead to Remote Code Execution CVE-2024-40779 — webkitgtk: webkit2gtk: Out-of-bounds read was addressed with improved bounds checking CVE-2024-40780 — webkitgtk: webkit2gtk: Out-of-bounds read was addressed with improved bounds checking CVE-2024-40782 — webkitgtk: webkit2gtk: Use-after-free was addressed with improved memory management CVE-2024-40789 — webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2024-44185 — webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2024-44244 — webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2024-54534 — webkit: Processing maliciously crafted web content may lead to memory corruption CVE-2025-24223 — webkitgtk: Processing maliciously crafted web content may lead to memory corruption CVE-2025-24264 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash CVE-2025-31204 — webkitgtk: Processing maliciously crafted web content may lead to memory corruption CVE-2025-31206 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash CVE-2025-31215 — webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash CVE-2025-43480 — webkitgtk: A malicious website may exfiltrate data cross-origin
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2024:9680
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2236842
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2238945
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253058
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2271456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2279689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2301841
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302067
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302069
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302070
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2302071
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2314697
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2314698
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2314700
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2314704
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2323263
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2323278
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9680.json