Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:18070 - Security Advisory
Issued:
2025-10-15
Updated:
2025-10-15

RHSA-2025:18070 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: webkit2gtk3 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43343)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2403598 - CVE-2025-43343 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash

CVEs

  • CVE-2025-43343

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
webkit2gtk3-2.50.1-1.el8_10.src.rpm SHA-256: 17eb4603b659e5c98d1133bb25b87707cbd1ec8b8088340d0c6d60582bbf2da7
x86_64
webkit2gtk3-2.50.1-1.el8_10.i686.rpm SHA-256: ae89ca4d5a476168ee9abf8d4cc610fc4ac553006655add6153dbcd7ffc5ff42
webkit2gtk3-2.50.1-1.el8_10.x86_64.rpm SHA-256: 03c9930736945f1db97f2b99a618f08c6592317c677301678e1ed087ed59c19e
webkit2gtk3-debuginfo-2.50.1-1.el8_10.i686.rpm SHA-256: 9fc53f1aa4ab59bfe2c76dca6d7b7cde356c21eef9b1182366941fb8e15ec6f0
webkit2gtk3-debuginfo-2.50.1-1.el8_10.x86_64.rpm SHA-256: 21f7aee5a88ccc61dcdc2d920fe13380ff691db7b1e79c3b695ead3705f02766
webkit2gtk3-debugsource-2.50.1-1.el8_10.i686.rpm SHA-256: 03879da58021c240c4e2e0d756b6d2e539caca28766f07629d9e99fba5859337
webkit2gtk3-debugsource-2.50.1-1.el8_10.x86_64.rpm SHA-256: c931dc15011acd0232d001108118465df43222f989a0b78f6b813c81eb35f84f
webkit2gtk3-devel-2.50.1-1.el8_10.i686.rpm SHA-256: 97c8c0e9ff7c80bee88b26bd18f6108aefb28ad195858dde977aa22d43361c54
webkit2gtk3-devel-2.50.1-1.el8_10.x86_64.rpm SHA-256: 58b46b6fbe8f0c72e4b11b8c4c21c16b8d135b0a5369017f11334bf741d7770e
webkit2gtk3-devel-debuginfo-2.50.1-1.el8_10.i686.rpm SHA-256: 6b0f47194220f7241de8f625073211e0d7c9cd97b623dad87c2ebf95ac53ea96
webkit2gtk3-devel-debuginfo-2.50.1-1.el8_10.x86_64.rpm SHA-256: 367104b7a6b33ea6e34222fd5f205f64f97bd7e0df4f3a97f884f74f47b1c4c1
webkit2gtk3-jsc-2.50.1-1.el8_10.i686.rpm SHA-256: e41264736e950f0034de2a408ea12807adbfbac8bda9bf014390ae92c02992e6
webkit2gtk3-jsc-2.50.1-1.el8_10.x86_64.rpm SHA-256: 90cff81c1f48653a81f6abe14261b47bf0567f0310432ef02ab88171844832a8
webkit2gtk3-jsc-debuginfo-2.50.1-1.el8_10.i686.rpm SHA-256: 3184e9f71c55323cc43f109d3f34626b169571f036ddf27cce3f11ff17de0acd
webkit2gtk3-jsc-debuginfo-2.50.1-1.el8_10.x86_64.rpm SHA-256: 9dd3e3c39dc63015abe6b1719941a45767515467486da01d31ffd606b54c6416
webkit2gtk3-jsc-devel-2.50.1-1.el8_10.i686.rpm SHA-256: 38c7d337b45f7fb04708e2190deff980117602009d95ade8ed0812f701b8644e
webkit2gtk3-jsc-devel-2.50.1-1.el8_10.x86_64.rpm SHA-256: 8899c23ba0c911b49c81537979f7c1c0deddda633f0ec57a0f6a9b2c985c6125
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el8_10.i686.rpm SHA-256: 2e503a5bf4231ca2b96b090284fe4d192a89096b0c059e336e2f61626481eecc
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el8_10.x86_64.rpm SHA-256: 996fdb33cb2b8f1bbcc6e91b5e9dc76150a1de873fa1d0f42371afbcefbf0d39

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
webkit2gtk3-2.50.1-1.el8_10.src.rpm SHA-256: 17eb4603b659e5c98d1133bb25b87707cbd1ec8b8088340d0c6d60582bbf2da7
s390x
webkit2gtk3-2.50.1-1.el8_10.s390x.rpm SHA-256: 47c3efa9b8d61b5a5976e3d8a157e0e0ebb854ab035129a07a29d3cad4333b09
webkit2gtk3-debuginfo-2.50.1-1.el8_10.s390x.rpm SHA-256: e7c982a4bd6ba562307db1242cf87db2fbfe68d009289ed8a0836a03e18e1092
webkit2gtk3-debugsource-2.50.1-1.el8_10.s390x.rpm SHA-256: 9557556cf1bc2b34761d712d403ebf93332121f5f23a040f6f3aede74c538177
webkit2gtk3-devel-2.50.1-1.el8_10.s390x.rpm SHA-256: f11d7e6dfed71345fda9a51c6fc538cd4140c16fd70978c60d6a1c177b1e3302
webkit2gtk3-devel-debuginfo-2.50.1-1.el8_10.s390x.rpm SHA-256: 3a72e31bb85d88ed7efae661ef78388eb6aca799de3d9c2242fe125bec03be56
webkit2gtk3-jsc-2.50.1-1.el8_10.s390x.rpm SHA-256: 064267f61b10a283efaddabc6ffe54d2113f6bcff8facc7f2f2abaa9c25ddb71
webkit2gtk3-jsc-debuginfo-2.50.1-1.el8_10.s390x.rpm SHA-256: 5139c02e42388146754634da535ed30f08ccdc65c1513d621233cda329feb071
webkit2gtk3-jsc-devel-2.50.1-1.el8_10.s390x.rpm SHA-256: febcb71f62f9a11a804403520d4229efdd523e99d36e85bce8fb5814ef80caff
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el8_10.s390x.rpm SHA-256: 895769779dcd25e0f376c1b7774376d2662c52265686ea7688c5d727fd685b34

Red Hat Enterprise Linux for Power, little endian 8

SRPM
webkit2gtk3-2.50.1-1.el8_10.src.rpm SHA-256: 17eb4603b659e5c98d1133bb25b87707cbd1ec8b8088340d0c6d60582bbf2da7
ppc64le
webkit2gtk3-2.50.1-1.el8_10.ppc64le.rpm SHA-256: fc15db5f3978eda6cd0a126264debde4ba76b4ce09a77d009fe60b80c9b5e112
webkit2gtk3-debuginfo-2.50.1-1.el8_10.ppc64le.rpm SHA-256: c25695351cedf824ffc481d2878a0f0e5bcdf847ee1f8b97f50cd7e1a71e2e5e
webkit2gtk3-debugsource-2.50.1-1.el8_10.ppc64le.rpm SHA-256: a2144291fee8e08a59049b3a9de5015822b83ebbf8761a9f8d267d709e0e2cb5
webkit2gtk3-devel-2.50.1-1.el8_10.ppc64le.rpm SHA-256: cae7f684bb5de07fa2d3cec7cd4726f6ded6a63ca75d1eea054c99e526faaa09
webkit2gtk3-devel-debuginfo-2.50.1-1.el8_10.ppc64le.rpm SHA-256: 500d878f785513ac53db40b29754d8e1a99468799e9fc6e264ea2e1b882af870
webkit2gtk3-jsc-2.50.1-1.el8_10.ppc64le.rpm SHA-256: 3ed8a24ec9414914b3996fc6c8a8ff676276587d50d75f3e78fa02c59e6ddfed
webkit2gtk3-jsc-debuginfo-2.50.1-1.el8_10.ppc64le.rpm SHA-256: ba5e8e19ff31fa7da9c71e2ed9a53aebfcc4bc6a12fdfa72504e1496496bb61f
webkit2gtk3-jsc-devel-2.50.1-1.el8_10.ppc64le.rpm SHA-256: 9dc367fc8e315eb676909d5dfe64de822334b2c335c7ac01318450f261bc8323
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el8_10.ppc64le.rpm SHA-256: e16c8fc38e957db5888074b42987867ec1bdf2842bd5e78f88ce9451e74659a1

Red Hat Enterprise Linux for ARM 64 8

SRPM
webkit2gtk3-2.50.1-1.el8_10.src.rpm SHA-256: 17eb4603b659e5c98d1133bb25b87707cbd1ec8b8088340d0c6d60582bbf2da7
aarch64
webkit2gtk3-2.50.1-1.el8_10.aarch64.rpm SHA-256: 19c01328fa585dab895c0548b876c8990d6b9223b0152826cc7cfb8224796ae1
webkit2gtk3-debuginfo-2.50.1-1.el8_10.aarch64.rpm SHA-256: c45fe7e2967c792d39f2c85bdf9a523d580ee210353bc1fa1b903540a0a8eb3c
webkit2gtk3-debugsource-2.50.1-1.el8_10.aarch64.rpm SHA-256: 849c021ff8df0b58ee6dae1dd9e1c41415f63c0781166c6d75225748c9b9429b
webkit2gtk3-devel-2.50.1-1.el8_10.aarch64.rpm SHA-256: adb67a8699b4523463a569267642a3d1710ae85112dc78558ddb47f4ee61918b
webkit2gtk3-devel-debuginfo-2.50.1-1.el8_10.aarch64.rpm SHA-256: 7ef3b2e836eb6e7a1bf82f8cec1be98711a1d1671c7d83a80868156c8a64a23b
webkit2gtk3-jsc-2.50.1-1.el8_10.aarch64.rpm SHA-256: 40c983a6d1b315ded9fa49facf2616a5ebe42fb8a65bc6d29de5d11e3c3696aa
webkit2gtk3-jsc-debuginfo-2.50.1-1.el8_10.aarch64.rpm SHA-256: b4fae6ba62a8d3960979a1b4eb22ba79bd70dff922ab4068ea892aca0e284293
webkit2gtk3-jsc-devel-2.50.1-1.el8_10.aarch64.rpm SHA-256: 16021e5d3437c48503ee114f42a1d23cf488067cf5f1dad2318cedc531638b33
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el8_10.aarch64.rpm SHA-256: 981b46f7b1453633173f37f9be8b63fe5142fd4fc1b6294acf98feed5a9ffc81

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility