Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:2072 - Security Advisory
Issued:
2023-05-02
Updated:
2023-05-02

RHSA-2023:2072 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libwebp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libwebp is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently.

Security Fix(es):

  • Mozilla: libwebp: Double-free in libwebp (CVE-2023-1999)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2 x86_64

Fixes

  • BZ - 2186102 - CVE-2023-1999 Mozilla: libwebp: Double-free in libwebp

CVEs

  • CVE-2023-1999

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 8.2

SRPM
libwebp-1.0.0-7.el8_2.src.rpm SHA-256: 3236a9cb3050af4b38d6c10fd75468225a476eb63d94f2747e7ca8c18ddc9967
x86_64
libwebp-1.0.0-7.el8_2.i686.rpm SHA-256: f311fcd9afbe8d800cf1a804ad2975934dc12e6fefe2813bc94287b90609cd3b
libwebp-1.0.0-7.el8_2.x86_64.rpm SHA-256: 0d1fc838e054934f3060327337ab4a504363aecf9a76ec891e37ca80405600ee
libwebp-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: 60ab5d815fad1947c58ac3c703bce0a5d9c50ae42fe77191ed330cbdc812b704
libwebp-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: 00cf0bdd9da90c914d1ccf90266cdc6a7d1271a38afa6c148a8cec6b2fe349d4
libwebp-debugsource-1.0.0-7.el8_2.i686.rpm SHA-256: 66d6ffa804ed880d305fe361fa9bed5657b356b7849e39f96de7c965c09320a7
libwebp-debugsource-1.0.0-7.el8_2.x86_64.rpm SHA-256: 9eb509dc345f5120fe37e15584bc1645dc27028a71f35d94030e998e0d6d46a4
libwebp-devel-1.0.0-7.el8_2.i686.rpm SHA-256: 7751f7aaa540b53549e168b650b762260c3b7d37fb63fec5d517d8fcb428f4b4
libwebp-devel-1.0.0-7.el8_2.x86_64.rpm SHA-256: 197fd8e794de75063d6f90a516a17f50d7fd7234f9eda86c2e254914afb97daf
libwebp-java-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: fcb24df4925dee8f15a7c7714f3a99d2454822c6a6f3c268453953281abef905
libwebp-java-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: f7e249254c3ea6c78495715d3dc6e966ed48ff0d7fb79667b18590e4b5eddaee
libwebp-tools-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: e5e3f9fdba23cd32eddd8d3b3aa248f182cdab51b96c308fbcd41c2292981dbc
libwebp-tools-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: ecd687bd05d36adb914a612bcb562ca15cc7cadc98ba09fbb565d282bb3f3538

Red Hat Enterprise Linux Server - TUS 8.2

SRPM
libwebp-1.0.0-7.el8_2.src.rpm SHA-256: 3236a9cb3050af4b38d6c10fd75468225a476eb63d94f2747e7ca8c18ddc9967
x86_64
libwebp-1.0.0-7.el8_2.i686.rpm SHA-256: f311fcd9afbe8d800cf1a804ad2975934dc12e6fefe2813bc94287b90609cd3b
libwebp-1.0.0-7.el8_2.x86_64.rpm SHA-256: 0d1fc838e054934f3060327337ab4a504363aecf9a76ec891e37ca80405600ee
libwebp-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: 60ab5d815fad1947c58ac3c703bce0a5d9c50ae42fe77191ed330cbdc812b704
libwebp-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: 00cf0bdd9da90c914d1ccf90266cdc6a7d1271a38afa6c148a8cec6b2fe349d4
libwebp-debugsource-1.0.0-7.el8_2.i686.rpm SHA-256: 66d6ffa804ed880d305fe361fa9bed5657b356b7849e39f96de7c965c09320a7
libwebp-debugsource-1.0.0-7.el8_2.x86_64.rpm SHA-256: 9eb509dc345f5120fe37e15584bc1645dc27028a71f35d94030e998e0d6d46a4
libwebp-devel-1.0.0-7.el8_2.i686.rpm SHA-256: 7751f7aaa540b53549e168b650b762260c3b7d37fb63fec5d517d8fcb428f4b4
libwebp-devel-1.0.0-7.el8_2.x86_64.rpm SHA-256: 197fd8e794de75063d6f90a516a17f50d7fd7234f9eda86c2e254914afb97daf
libwebp-java-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: fcb24df4925dee8f15a7c7714f3a99d2454822c6a6f3c268453953281abef905
libwebp-java-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: f7e249254c3ea6c78495715d3dc6e966ed48ff0d7fb79667b18590e4b5eddaee
libwebp-tools-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: e5e3f9fdba23cd32eddd8d3b3aa248f182cdab51b96c308fbcd41c2292981dbc
libwebp-tools-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: ecd687bd05d36adb914a612bcb562ca15cc7cadc98ba09fbb565d282bb3f3538

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.2

SRPM
libwebp-1.0.0-7.el8_2.src.rpm SHA-256: 3236a9cb3050af4b38d6c10fd75468225a476eb63d94f2747e7ca8c18ddc9967
ppc64le
libwebp-1.0.0-7.el8_2.ppc64le.rpm SHA-256: 8321fa232f1253d474b702cce1e83261c18a8af298e88b5671f4e3501b1e2d9c
libwebp-debuginfo-1.0.0-7.el8_2.ppc64le.rpm SHA-256: a50c2be2b8f9b4e90ed401b14366fe0df9c50b554abb314ebc261cac2265a5d4
libwebp-debugsource-1.0.0-7.el8_2.ppc64le.rpm SHA-256: 9eb1a52bde0fb88530b8b5e11878accc1af2202908f6206f06a08f267a4a8d1f
libwebp-devel-1.0.0-7.el8_2.ppc64le.rpm SHA-256: 8f3bd19c94131479e5a2bf4ced622a7779c96c121c30104bd9a2b4b8588dfec7
libwebp-java-debuginfo-1.0.0-7.el8_2.ppc64le.rpm SHA-256: 2f0946d04c38f621771c576ee936a62990012b1932a92a29d12d7b7b9516453c
libwebp-tools-debuginfo-1.0.0-7.el8_2.ppc64le.rpm SHA-256: e26b8b41601b1e4a32645a8f0601e8b2eca257f2fed671a7ddce671ea2e12a4e

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.2

SRPM
libwebp-1.0.0-7.el8_2.src.rpm SHA-256: 3236a9cb3050af4b38d6c10fd75468225a476eb63d94f2747e7ca8c18ddc9967
x86_64
libwebp-1.0.0-7.el8_2.i686.rpm SHA-256: f311fcd9afbe8d800cf1a804ad2975934dc12e6fefe2813bc94287b90609cd3b
libwebp-1.0.0-7.el8_2.x86_64.rpm SHA-256: 0d1fc838e054934f3060327337ab4a504363aecf9a76ec891e37ca80405600ee
libwebp-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: 60ab5d815fad1947c58ac3c703bce0a5d9c50ae42fe77191ed330cbdc812b704
libwebp-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: 00cf0bdd9da90c914d1ccf90266cdc6a7d1271a38afa6c148a8cec6b2fe349d4
libwebp-debugsource-1.0.0-7.el8_2.i686.rpm SHA-256: 66d6ffa804ed880d305fe361fa9bed5657b356b7849e39f96de7c965c09320a7
libwebp-debugsource-1.0.0-7.el8_2.x86_64.rpm SHA-256: 9eb509dc345f5120fe37e15584bc1645dc27028a71f35d94030e998e0d6d46a4
libwebp-devel-1.0.0-7.el8_2.i686.rpm SHA-256: 7751f7aaa540b53549e168b650b762260c3b7d37fb63fec5d517d8fcb428f4b4
libwebp-devel-1.0.0-7.el8_2.x86_64.rpm SHA-256: 197fd8e794de75063d6f90a516a17f50d7fd7234f9eda86c2e254914afb97daf
libwebp-java-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: fcb24df4925dee8f15a7c7714f3a99d2454822c6a6f3c268453953281abef905
libwebp-java-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: f7e249254c3ea6c78495715d3dc6e966ed48ff0d7fb79667b18590e4b5eddaee
libwebp-tools-debuginfo-1.0.0-7.el8_2.i686.rpm SHA-256: e5e3f9fdba23cd32eddd8d3b3aa248f182cdab51b96c308fbcd41c2292981dbc
libwebp-tools-debuginfo-1.0.0-7.el8_2.x86_64.rpm SHA-256: ecd687bd05d36adb914a612bcb562ca15cc7cadc98ba09fbb565d282bb3f3538

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility