Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:5236 - Security Advisory
Issued:
2023-09-19
Updated:
2023-09-19

RHSA-2023:5236 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libwebp: critical security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libwebp is now available for Red Hat Enterprise Linux 8.1 Update
Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which give
a detailed severity rating, is available for each vulnerability from the CVE
link(s) in the References section.

Description

The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently.

Security Fix(es):

  • libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 2238431 - CVE-2023-4863 libwebp: Heap buffer overflow in WebP Codec

CVEs

  • CVE-2023-4863
  • CVE-2023-5129

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
libwebp-1.0.0-5.2.el8_1.1.src.rpm SHA-256: e1e5851c9d6a0117168a7fcdb2dab8c8c658a15ad6a90fb8c0037e120e9c1f62
ppc64le
libwebp-1.0.0-5.2.el8_1.1.ppc64le.rpm SHA-256: 74596bfdb6c1b16d9be25aea0b024f2f7479035918d6dce6d673bdc0f63512af
libwebp-debuginfo-1.0.0-5.2.el8_1.1.ppc64le.rpm SHA-256: fc54e5aaa2b7bf981a54cc8d5cc07ef80c053354bfb22b01118f5076eae161a3
libwebp-debugsource-1.0.0-5.2.el8_1.1.ppc64le.rpm SHA-256: 0c569dc1822fb3cdcc4664170bd991e9563fb43a3fe46ad231c4189402a25aee
libwebp-devel-1.0.0-5.2.el8_1.1.ppc64le.rpm SHA-256: 34c1a51060b97fcaae824cab9590b46bed41abc9833db2f43cd059f19ce30e58
libwebp-java-debuginfo-1.0.0-5.2.el8_1.1.ppc64le.rpm SHA-256: 0e2d5122a9238e9fce92198d718a820738bd2dd74f03cfa5c9085bad9f98afc6
libwebp-tools-debuginfo-1.0.0-5.2.el8_1.1.ppc64le.rpm SHA-256: cc3185849fb3acf447a753b281f4ffa43a333a01613604b95cb600425be68715

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
libwebp-1.0.0-5.2.el8_1.1.src.rpm SHA-256: e1e5851c9d6a0117168a7fcdb2dab8c8c658a15ad6a90fb8c0037e120e9c1f62
x86_64
libwebp-1.0.0-5.2.el8_1.1.i686.rpm SHA-256: 4fc0fb0cd385e5e9c54568e3a8c6e3d3c69f8c1c8526c784b6884e9550030433
libwebp-1.0.0-5.2.el8_1.1.x86_64.rpm SHA-256: 403d57d0c0c67979a5999e08122406503aa16a17f6ac1b9e03622afe4d6a3d2b
libwebp-debuginfo-1.0.0-5.2.el8_1.1.i686.rpm SHA-256: 8d76335d048655f285b3d5e9c62eea7861c7ae94ab3cfc71071a12ae1ce7cfa7
libwebp-debuginfo-1.0.0-5.2.el8_1.1.x86_64.rpm SHA-256: fa339138b6d264f6a4de747f3e4938d629544818d01b50be071c2058c56fd7a0
libwebp-debugsource-1.0.0-5.2.el8_1.1.i686.rpm SHA-256: d9e3ac7661e0bdc2c5cccba8c3a1323ef345a6f09916c18e757b77ffdb8a2d9b
libwebp-debugsource-1.0.0-5.2.el8_1.1.x86_64.rpm SHA-256: 6b2379296c3f4ba261a3775caff15f8b64cc89ed3e5f0faef847cc8011683e0b
libwebp-devel-1.0.0-5.2.el8_1.1.i686.rpm SHA-256: 261a36db37f550d59d886d08652204e1d725f879fc77be4fcf150235ddca3b6f
libwebp-devel-1.0.0-5.2.el8_1.1.x86_64.rpm SHA-256: f38ebfda9ecd4b920d549136da236f2c714bfa1e2aed03fbeb169b14a926dab4
libwebp-java-debuginfo-1.0.0-5.2.el8_1.1.i686.rpm SHA-256: 73bde59848d14159eb6ce9596c3eb052e6154ec9892207db48a63f06341cc996
libwebp-java-debuginfo-1.0.0-5.2.el8_1.1.x86_64.rpm SHA-256: 0bbc681a5322ff6c55b490bc86441ca49c0f526b74153906e5688308d819b103
libwebp-tools-debuginfo-1.0.0-5.2.el8_1.1.i686.rpm SHA-256: cf17460b0ab0eaf154675fbe44daf5ead27b1e26c3c81ab010bf57d817da5f13
libwebp-tools-debuginfo-1.0.0-5.2.el8_1.1.x86_64.rpm SHA-256: cc6851920d54a72ec5acc80c7c74c7040094671e8000f7b5c61f39cea7e3736f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility