Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2021:2364 - Security Advisory
Issued:
2021-06-09
Updated:
2021-06-09

RHSA-2021:2364 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libwebp security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libwebp is now available for Red Hat Enterprise Linux 8.2 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently.

Security Fix(es):

  • libwebp: heap-based buffer overflow in PutLE16() (CVE-2018-25011)
  • libwebp: heap-based buffer overflow in WebPDecode*Into functions (CVE-2020-36328)
  • libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c (CVE-2020-36329)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.2 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.2 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.2 ppc64le
  • Red Hat Enterprise Linux Server - TUS 8.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.2 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64

Fixes

  • BZ - 1956829 - CVE-2020-36328 libwebp: heap-based buffer overflow in WebPDecode*Into functions
  • BZ - 1956843 - CVE-2020-36329 libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c
  • BZ - 1956919 - CVE-2018-25011 libwebp: heap-based buffer overflow in PutLE16()

CVEs

  • CVE-2018-25011
  • CVE-2020-36328
  • CVE-2020-36329

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.2

SRPM
libwebp-1.0.0-4.el8_2.src.rpm SHA-256: 57e13a8194cb07a827bcbfe342bf582c29d434eb2e0d737ed341daf9802b0d04
x86_64
libwebp-1.0.0-4.el8_2.i686.rpm SHA-256: 8929765234c078f346b3744447ebe4185441174b6328422adba6f3f43e261fdf
libwebp-1.0.0-4.el8_2.x86_64.rpm SHA-256: 1d9ce5d93cb80dcc2b09f912d067e9cbdbd484666e04392c048338f9c2f432f2
libwebp-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: f92d93638951bd9d0ed9a8e9b090c008507da3fb0f43f1e79e49f58d6e616626
libwebp-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: b85d9c05d3fb6a811692c2a51f907b18afa0c0ff0ff40b46a80d569fbc3a6ca6
libwebp-debugsource-1.0.0-4.el8_2.i686.rpm SHA-256: 7d835ea4e74abf6983cc4da628fbeeddb640d8df84bb2d78a3ff441da1693eb2
libwebp-debugsource-1.0.0-4.el8_2.x86_64.rpm SHA-256: eb90a038e965776a7fdad4ee4611b903487b9505209714b870b2db74995d3273
libwebp-devel-1.0.0-4.el8_2.i686.rpm SHA-256: b5bf90900e6eb01e54323b5984eed4d7c25fd8fd5c39919507b84c0af6793f6e
libwebp-devel-1.0.0-4.el8_2.x86_64.rpm SHA-256: 78090afa9da9eef1f4297d3dbb4661c70a101280310417910b32b7d22ab76fc9
libwebp-java-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: f3d716c5f63eb92379778178eaf5e795ac2059bdba00ba764440e3152d03b778
libwebp-java-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: 50a3ac4ce33ac508ef36efe501b7170a480f1d44e7565c4a73b32fb6e43430a8
libwebp-tools-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: b811fef79e3dde2c6b819920f22b0bda80e1e6d1f4578c601b6cc33218c84789
libwebp-tools-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: 2873d29956db9cdb29eefffd9a5b1698146089985bf46951d407d04c7bf18da8

Red Hat Enterprise Linux Server - AUS 8.2

SRPM
libwebp-1.0.0-4.el8_2.src.rpm SHA-256: 57e13a8194cb07a827bcbfe342bf582c29d434eb2e0d737ed341daf9802b0d04
x86_64
libwebp-1.0.0-4.el8_2.i686.rpm SHA-256: 8929765234c078f346b3744447ebe4185441174b6328422adba6f3f43e261fdf
libwebp-1.0.0-4.el8_2.x86_64.rpm SHA-256: 1d9ce5d93cb80dcc2b09f912d067e9cbdbd484666e04392c048338f9c2f432f2
libwebp-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: f92d93638951bd9d0ed9a8e9b090c008507da3fb0f43f1e79e49f58d6e616626
libwebp-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: b85d9c05d3fb6a811692c2a51f907b18afa0c0ff0ff40b46a80d569fbc3a6ca6
libwebp-debugsource-1.0.0-4.el8_2.i686.rpm SHA-256: 7d835ea4e74abf6983cc4da628fbeeddb640d8df84bb2d78a3ff441da1693eb2
libwebp-debugsource-1.0.0-4.el8_2.x86_64.rpm SHA-256: eb90a038e965776a7fdad4ee4611b903487b9505209714b870b2db74995d3273
libwebp-devel-1.0.0-4.el8_2.i686.rpm SHA-256: b5bf90900e6eb01e54323b5984eed4d7c25fd8fd5c39919507b84c0af6793f6e
libwebp-devel-1.0.0-4.el8_2.x86_64.rpm SHA-256: 78090afa9da9eef1f4297d3dbb4661c70a101280310417910b32b7d22ab76fc9
libwebp-java-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: f3d716c5f63eb92379778178eaf5e795ac2059bdba00ba764440e3152d03b778
libwebp-java-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: 50a3ac4ce33ac508ef36efe501b7170a480f1d44e7565c4a73b32fb6e43430a8
libwebp-tools-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: b811fef79e3dde2c6b819920f22b0bda80e1e6d1f4578c601b6cc33218c84789
libwebp-tools-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: 2873d29956db9cdb29eefffd9a5b1698146089985bf46951d407d04c7bf18da8

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.2

SRPM
libwebp-1.0.0-4.el8_2.src.rpm SHA-256: 57e13a8194cb07a827bcbfe342bf582c29d434eb2e0d737ed341daf9802b0d04
s390x
libwebp-1.0.0-4.el8_2.s390x.rpm SHA-256: 301163a81a88ebea4936bdab8e5671ee8ebdd9a05784b3dd8b7c669bce2dad8e
libwebp-debuginfo-1.0.0-4.el8_2.s390x.rpm SHA-256: 1db7694e95064344626bfcbbd66eaa6ce3c75959951cc464285c1dd188adbcac
libwebp-debugsource-1.0.0-4.el8_2.s390x.rpm SHA-256: a408eca846ca5442e1130b8bb78f6e315c383fed4be9057179e18c3927c860b9
libwebp-devel-1.0.0-4.el8_2.s390x.rpm SHA-256: 211904ab609ceff2bd43a7d24daffb368746c592bb54223da91194b9419895fa
libwebp-java-debuginfo-1.0.0-4.el8_2.s390x.rpm SHA-256: e6a7656c2b2c8b0a08b0049520bf9766ca9aebd02d053463de8f8ab9ecaba1ec
libwebp-tools-debuginfo-1.0.0-4.el8_2.s390x.rpm SHA-256: fa5e6469264b679110078fa07b54b14e84f2aa061289cbcad2de5893f61e6557

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.2

SRPM
libwebp-1.0.0-4.el8_2.src.rpm SHA-256: 57e13a8194cb07a827bcbfe342bf582c29d434eb2e0d737ed341daf9802b0d04
ppc64le
libwebp-1.0.0-4.el8_2.ppc64le.rpm SHA-256: 97eb7e0ac9ab71f95be3a8bee3df2c6b5dd125fd709b1b83b7f971340480e69d
libwebp-debuginfo-1.0.0-4.el8_2.ppc64le.rpm SHA-256: aad09f6b6cbe9eb9438cb6d601b62aa84a83c4568f97514649cf739af4c4ce71
libwebp-debugsource-1.0.0-4.el8_2.ppc64le.rpm SHA-256: 9ab154dbdb75a6b815a02884a724770f62ef6f2631139c023c0ba9db86ee2545
libwebp-devel-1.0.0-4.el8_2.ppc64le.rpm SHA-256: e8973cd93c4be51da726c7f7a7432a8143d8cbb3a769e3287f27c9bf0dc5d4c0
libwebp-java-debuginfo-1.0.0-4.el8_2.ppc64le.rpm SHA-256: 535e2ac5aadbb67dc5ca59248bce8a00bfbd55882a12f74fae30b992c4b82d95
libwebp-tools-debuginfo-1.0.0-4.el8_2.ppc64le.rpm SHA-256: f611a3e1ab8d0325a294cb00929829fda319092d24939442d5c92e6bbb80a37e

Red Hat Enterprise Linux Server - TUS 8.2

SRPM
libwebp-1.0.0-4.el8_2.src.rpm SHA-256: 57e13a8194cb07a827bcbfe342bf582c29d434eb2e0d737ed341daf9802b0d04
x86_64
libwebp-1.0.0-4.el8_2.i686.rpm SHA-256: 8929765234c078f346b3744447ebe4185441174b6328422adba6f3f43e261fdf
libwebp-1.0.0-4.el8_2.x86_64.rpm SHA-256: 1d9ce5d93cb80dcc2b09f912d067e9cbdbd484666e04392c048338f9c2f432f2
libwebp-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: f92d93638951bd9d0ed9a8e9b090c008507da3fb0f43f1e79e49f58d6e616626
libwebp-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: b85d9c05d3fb6a811692c2a51f907b18afa0c0ff0ff40b46a80d569fbc3a6ca6
libwebp-debugsource-1.0.0-4.el8_2.i686.rpm SHA-256: 7d835ea4e74abf6983cc4da628fbeeddb640d8df84bb2d78a3ff441da1693eb2
libwebp-debugsource-1.0.0-4.el8_2.x86_64.rpm SHA-256: eb90a038e965776a7fdad4ee4611b903487b9505209714b870b2db74995d3273
libwebp-devel-1.0.0-4.el8_2.i686.rpm SHA-256: b5bf90900e6eb01e54323b5984eed4d7c25fd8fd5c39919507b84c0af6793f6e
libwebp-devel-1.0.0-4.el8_2.x86_64.rpm SHA-256: 78090afa9da9eef1f4297d3dbb4661c70a101280310417910b32b7d22ab76fc9
libwebp-java-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: f3d716c5f63eb92379778178eaf5e795ac2059bdba00ba764440e3152d03b778
libwebp-java-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: 50a3ac4ce33ac508ef36efe501b7170a480f1d44e7565c4a73b32fb6e43430a8
libwebp-tools-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: b811fef79e3dde2c6b819920f22b0bda80e1e6d1f4578c601b6cc33218c84789
libwebp-tools-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: 2873d29956db9cdb29eefffd9a5b1698146089985bf46951d407d04c7bf18da8

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.2

SRPM
libwebp-1.0.0-4.el8_2.src.rpm SHA-256: 57e13a8194cb07a827bcbfe342bf582c29d434eb2e0d737ed341daf9802b0d04
aarch64
libwebp-1.0.0-4.el8_2.aarch64.rpm SHA-256: 46d1801b07945dc0de5a6d58c0303b3b9de10570958200b3e6d11462b68ad6e0
libwebp-debuginfo-1.0.0-4.el8_2.aarch64.rpm SHA-256: 47533134811a992bd0232bea53f81101383240c119b966945b402280aef6a7ff
libwebp-debugsource-1.0.0-4.el8_2.aarch64.rpm SHA-256: 4493177240b316a189e4ff863544942c1d6473b52ea045091f5089227ba7da86
libwebp-devel-1.0.0-4.el8_2.aarch64.rpm SHA-256: 96205f58a699285db11a60da220f95fcea6d800990b6db7e9ca9462f169abe61
libwebp-java-debuginfo-1.0.0-4.el8_2.aarch64.rpm SHA-256: b0669d7f5adbc3b6f0373c0cd16917cbb0c8b42c2e5ae669af3f3e6051d7dcd0
libwebp-tools-debuginfo-1.0.0-4.el8_2.aarch64.rpm SHA-256: 4833963e68c2e12a0c5a504b2e327aae612d8be2768d475da37f14125d178de6

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2

SRPM
libwebp-1.0.0-4.el8_2.src.rpm SHA-256: 57e13a8194cb07a827bcbfe342bf582c29d434eb2e0d737ed341daf9802b0d04
ppc64le
libwebp-1.0.0-4.el8_2.ppc64le.rpm SHA-256: 97eb7e0ac9ab71f95be3a8bee3df2c6b5dd125fd709b1b83b7f971340480e69d
libwebp-debuginfo-1.0.0-4.el8_2.ppc64le.rpm SHA-256: aad09f6b6cbe9eb9438cb6d601b62aa84a83c4568f97514649cf739af4c4ce71
libwebp-debugsource-1.0.0-4.el8_2.ppc64le.rpm SHA-256: 9ab154dbdb75a6b815a02884a724770f62ef6f2631139c023c0ba9db86ee2545
libwebp-devel-1.0.0-4.el8_2.ppc64le.rpm SHA-256: e8973cd93c4be51da726c7f7a7432a8143d8cbb3a769e3287f27c9bf0dc5d4c0
libwebp-java-debuginfo-1.0.0-4.el8_2.ppc64le.rpm SHA-256: 535e2ac5aadbb67dc5ca59248bce8a00bfbd55882a12f74fae30b992c4b82d95
libwebp-tools-debuginfo-1.0.0-4.el8_2.ppc64le.rpm SHA-256: f611a3e1ab8d0325a294cb00929829fda319092d24939442d5c92e6bbb80a37e

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2

SRPM
libwebp-1.0.0-4.el8_2.src.rpm SHA-256: 57e13a8194cb07a827bcbfe342bf582c29d434eb2e0d737ed341daf9802b0d04
x86_64
libwebp-1.0.0-4.el8_2.i686.rpm SHA-256: 8929765234c078f346b3744447ebe4185441174b6328422adba6f3f43e261fdf
libwebp-1.0.0-4.el8_2.x86_64.rpm SHA-256: 1d9ce5d93cb80dcc2b09f912d067e9cbdbd484666e04392c048338f9c2f432f2
libwebp-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: f92d93638951bd9d0ed9a8e9b090c008507da3fb0f43f1e79e49f58d6e616626
libwebp-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: b85d9c05d3fb6a811692c2a51f907b18afa0c0ff0ff40b46a80d569fbc3a6ca6
libwebp-debugsource-1.0.0-4.el8_2.i686.rpm SHA-256: 7d835ea4e74abf6983cc4da628fbeeddb640d8df84bb2d78a3ff441da1693eb2
libwebp-debugsource-1.0.0-4.el8_2.x86_64.rpm SHA-256: eb90a038e965776a7fdad4ee4611b903487b9505209714b870b2db74995d3273
libwebp-devel-1.0.0-4.el8_2.i686.rpm SHA-256: b5bf90900e6eb01e54323b5984eed4d7c25fd8fd5c39919507b84c0af6793f6e
libwebp-devel-1.0.0-4.el8_2.x86_64.rpm SHA-256: 78090afa9da9eef1f4297d3dbb4661c70a101280310417910b32b7d22ab76fc9
libwebp-java-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: f3d716c5f63eb92379778178eaf5e795ac2059bdba00ba764440e3152d03b778
libwebp-java-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: 50a3ac4ce33ac508ef36efe501b7170a480f1d44e7565c4a73b32fb6e43430a8
libwebp-tools-debuginfo-1.0.0-4.el8_2.i686.rpm SHA-256: b811fef79e3dde2c6b819920f22b0bda80e1e6d1f4578c601b6cc33218c84789
libwebp-tools-debuginfo-1.0.0-4.el8_2.x86_64.rpm SHA-256: 2873d29956db9cdb29eefffd9a5b1698146089985bf46951d407d04c7bf18da8

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility