Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:20922 - Security Advisory
Issued:
2025-11-11
Updated:
2025-11-11

RHSA-2025:20922 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: webkit2gtk3 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43272)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43342)
  • webkitgtk: A website may be able to access sensor information without user consent (CVE-2025-43356)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43368)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43343)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2397626 - CVE-2025-43272 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
  • BZ - 2397627 - CVE-2025-43342 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2397628 - CVE-2025-43356 webkitgtk: A website may be able to access sensor information without user consent
  • BZ - 2397630 - CVE-2025-43368 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
  • BZ - 2403598 - CVE-2025-43343 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash

CVEs

  • CVE-2025-43272
  • CVE-2025-43342
  • CVE-2025-43343
  • CVE-2025-43356
  • CVE-2025-43368

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
webkit2gtk3-2.50.1-1.el9_7.src.rpm SHA-256: e1b1c7add14caba6e201ba1daa0dc6d547452a49b438b425a0132285c0982356
x86_64
webkit2gtk3-2.50.1-1.el9_7.i686.rpm SHA-256: 404e615599e692ba7c603031275deb4a2ced4e0a0598e203cb26c2ec6237d201
webkit2gtk3-2.50.1-1.el9_7.x86_64.rpm SHA-256: c53f0792ce12c4ed8fdc6d5301e83c33b044807279e92475c35cc6a81c9c5b32
webkit2gtk3-debuginfo-2.50.1-1.el9_7.i686.rpm SHA-256: ee4ff97fc1b5ee3a39b059406587ae4c712781e04be2ba17e1b3cdeae169db18
webkit2gtk3-debuginfo-2.50.1-1.el9_7.x86_64.rpm SHA-256: 296941f82acef977ce869f6c27f081b162a8f6ddddcb1200b95e6f317926e40a
webkit2gtk3-debugsource-2.50.1-1.el9_7.i686.rpm SHA-256: f71b9447c4b55b9cddd38c5be3b8607a1fb32342cd35ef18b1ee245862e32c35
webkit2gtk3-debugsource-2.50.1-1.el9_7.x86_64.rpm SHA-256: 09dbca97c9f3444ff1931fa9e557bb5f0ac1d3b60473e2ebb2276ced349e3641
webkit2gtk3-devel-2.50.1-1.el9_7.i686.rpm SHA-256: 60528645563667f02b630ef074e539bfb10657ddef26c832e33bf058c0293edd
webkit2gtk3-devel-2.50.1-1.el9_7.x86_64.rpm SHA-256: cfd3b232964c785f4790406b7e4195726d826e68179505b3acdbcf05cf0d6898
webkit2gtk3-devel-debuginfo-2.50.1-1.el9_7.i686.rpm SHA-256: 18c1764900a06f1e01ce2c77c8734bd09d96dfe1dc532700bd91cd428de71f90
webkit2gtk3-devel-debuginfo-2.50.1-1.el9_7.x86_64.rpm SHA-256: 57a144db24d51797528425eff6b23845611fa34935e3f892b96306f5e19c27ad
webkit2gtk3-jsc-2.50.1-1.el9_7.i686.rpm SHA-256: f0f9860f4c8cab9b6577240edfd1fa0cbe82a6c2ea48e77e06fddcd67a3d42a5
webkit2gtk3-jsc-2.50.1-1.el9_7.x86_64.rpm SHA-256: 22ca3bfd5ad9dbcf96674465da6abfd0880f4ce8117e8c39c598c9e40f541f3d
webkit2gtk3-jsc-debuginfo-2.50.1-1.el9_7.i686.rpm SHA-256: a67227ffebe7d8ca7280b87e375a6a0535388b132743a14a89002295a4d6313f
webkit2gtk3-jsc-debuginfo-2.50.1-1.el9_7.x86_64.rpm SHA-256: 8ad0713fb5b4ebdefdf7bc2c69dea41863b386332fdccc7b92d3235ff9cd91c0
webkit2gtk3-jsc-devel-2.50.1-1.el9_7.i686.rpm SHA-256: 2ff459d16d53b3d21883b0fb7615256aa15541b8adb8ddb396d0a106ff596f74
webkit2gtk3-jsc-devel-2.50.1-1.el9_7.x86_64.rpm SHA-256: 2ed21feb7bf3698dbd34cf293462f5092a82a84ab82b786eeeb8b0b6f3967945
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el9_7.i686.rpm SHA-256: f9719a9a43b3706b9d207a885f0eaf977782be16695c64735b207329be55028a
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el9_7.x86_64.rpm SHA-256: 9f5948215835292cd73e33f41c06f26abd8817cccaf12478afcc100758da3217

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
webkit2gtk3-2.50.1-1.el9_7.src.rpm SHA-256: e1b1c7add14caba6e201ba1daa0dc6d547452a49b438b425a0132285c0982356
s390x
webkit2gtk3-2.50.1-1.el9_7.s390x.rpm SHA-256: 749afda0e82d1cc370fc36e8c68c4ab9be736ce8ee547ef214234d6e0952c8c0
webkit2gtk3-debuginfo-2.50.1-1.el9_7.s390x.rpm SHA-256: d82a316eab98a964e6425b613e27791d917cd398560b6156a87409b5e15b2bc6
webkit2gtk3-debugsource-2.50.1-1.el9_7.s390x.rpm SHA-256: 90d9626496f9aa2a8db256ff7705580da8037bf455424e690aa5e49477c5eb2c
webkit2gtk3-devel-2.50.1-1.el9_7.s390x.rpm SHA-256: c85a9cad4e8f0d322f06a1a6c9bfeb333328d57666075981cd307f5d896afd5f
webkit2gtk3-devel-debuginfo-2.50.1-1.el9_7.s390x.rpm SHA-256: 79a17491d9f8ab5cb026584a306e0fb2bff73c6d03fb00ab852c2023be321f95
webkit2gtk3-jsc-2.50.1-1.el9_7.s390x.rpm SHA-256: a262841f0fee6949089f1dcac9f161d94b60e67f380c86c57e6634139e700a69
webkit2gtk3-jsc-debuginfo-2.50.1-1.el9_7.s390x.rpm SHA-256: 30f2b028137c1cecc3f122bbe8c96e37fe71d25893a14b161acb57ed90850f99
webkit2gtk3-jsc-devel-2.50.1-1.el9_7.s390x.rpm SHA-256: 63d59e7fe0c853b3e5c59443311c3e84cea208b16c43c485180d5fa4f58e45e7
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el9_7.s390x.rpm SHA-256: 5ca1eb21d6ae980f8b07a4733157c4d1e158323d58d933ce7fd2b774a157ace9

Red Hat Enterprise Linux for Power, little endian 9

SRPM
webkit2gtk3-2.50.1-1.el9_7.src.rpm SHA-256: e1b1c7add14caba6e201ba1daa0dc6d547452a49b438b425a0132285c0982356
ppc64le
webkit2gtk3-2.50.1-1.el9_7.ppc64le.rpm SHA-256: 3f6236bef48c8ad9812b5e69994734c9dcefbb968ba81872dadbfe820ec59d0e
webkit2gtk3-debuginfo-2.50.1-1.el9_7.ppc64le.rpm SHA-256: 80f47b92c7c938154de36ece9c2ace5f3c6b74261dd433ac2a1937f138e3d6cc
webkit2gtk3-debugsource-2.50.1-1.el9_7.ppc64le.rpm SHA-256: f808db8633e1c40f478c61cc5498720696ef8189e022ba207986790aa11ef3a9
webkit2gtk3-devel-2.50.1-1.el9_7.ppc64le.rpm SHA-256: a37d03952cff7e98e18ba0b95c2f513d54c0d8c4a7a29bf9880563296bfce16f
webkit2gtk3-devel-debuginfo-2.50.1-1.el9_7.ppc64le.rpm SHA-256: 6a39cffb4a1d89b0b3b3390cbf22c48bf9ee5d35fb81c58b7453dfe1b216b643
webkit2gtk3-jsc-2.50.1-1.el9_7.ppc64le.rpm SHA-256: 2125b5a469296638ec8a76662caee88236ccbdf21b6d5dde386066d887651d53
webkit2gtk3-jsc-debuginfo-2.50.1-1.el9_7.ppc64le.rpm SHA-256: 7946c35af30e8f7d1c03ab5bee66efc962329f7b5ce1ad31979e05f09292c45c
webkit2gtk3-jsc-devel-2.50.1-1.el9_7.ppc64le.rpm SHA-256: e431c58b386445db09023fe6e0183cf56f4e9515985b03efc50543e39d2ce3a6
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el9_7.ppc64le.rpm SHA-256: 20a35dd816ae8d5690c2a5663bec237adb7c695d9df35c87196350cff2612102

Red Hat Enterprise Linux for ARM 64 9

SRPM
webkit2gtk3-2.50.1-1.el9_7.src.rpm SHA-256: e1b1c7add14caba6e201ba1daa0dc6d547452a49b438b425a0132285c0982356
aarch64
webkit2gtk3-2.50.1-1.el9_7.aarch64.rpm SHA-256: 50e32f64bf6909f295f59b5655fed4c0e87a5aa95888c29c69ced54898b1aeaa
webkit2gtk3-debuginfo-2.50.1-1.el9_7.aarch64.rpm SHA-256: 341e35bbedf0c85e00c9a6cd292864dbe9b5ee9dcb034597e5aa7badbd771846
webkit2gtk3-debugsource-2.50.1-1.el9_7.aarch64.rpm SHA-256: 5aef829f322cd8107865a43fe7d09544fdc8d0b85d09b6501df4349fbd7385dd
webkit2gtk3-devel-2.50.1-1.el9_7.aarch64.rpm SHA-256: edf5df8eae37c32301c7d4b97bc1d72e9658d046c18c0fa954d2acb533296b83
webkit2gtk3-devel-debuginfo-2.50.1-1.el9_7.aarch64.rpm SHA-256: b114946e9780491572f31fc2f9710389f0a3cfdd257e4ae9d9fcf5ec8fc40c7b
webkit2gtk3-jsc-2.50.1-1.el9_7.aarch64.rpm SHA-256: d1acbe92ef464680ebe950c2194556eac55581b8bead5f389e706d5dd79d801e
webkit2gtk3-jsc-debuginfo-2.50.1-1.el9_7.aarch64.rpm SHA-256: 87c08f47c2ce45aab1368e03c1c7d3036cc98819a40ee1d8d4ef3fd57ccea02f
webkit2gtk3-jsc-devel-2.50.1-1.el9_7.aarch64.rpm SHA-256: a6fad34a02c904db12afd2a1bf40e1b1812664be4b0e2287fd8f2dca4a946e3f
webkit2gtk3-jsc-devel-debuginfo-2.50.1-1.el9_7.aarch64.rpm SHA-256: 4bac96c657cbf44d3cd07e8795b4d9ff8ff8d80207ef3716542d180f54c002f3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility