Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22789 - Security Advisory
Issued:
2025-12-08
Updated:
2025-12-11

RHSA-2025:22789 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: webkit2gtk3 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

  • webkit: WebKitGTK / WPE WebKit: Out-of-bounds read and integer underflow vulnerability leading to DoS (CVE-2025-13502)
  • webkitgtk: A website may exfiltrate image data cross-origin (CVE-2025-43392)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43425)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43427)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43429)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43430)
  • webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2025-43431)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43432)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43434)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43440)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43443)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43421)
  • webkit: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop (CVE-2025-13947)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43458)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-66287)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2416300 - CVE-2025-13502 webkit: WebKitGTK / WPE WebKit: Out-of-bounds read and integer underflow vulnerability leading to DoS
  • BZ - 2416325 - CVE-2025-43392 webkitgtk: A website may exfiltrate image data cross-origin
  • BZ - 2416327 - CVE-2025-43425 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416329 - CVE-2025-43427 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416330 - CVE-2025-43429 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416331 - CVE-2025-43430 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416332 - CVE-2025-43431 webkitgtk: Processing maliciously crafted web content may lead to memory corruption
  • BZ - 2416334 - CVE-2025-43432 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416335 - CVE-2025-43434 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
  • BZ - 2416336 - CVE-2025-43440 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416337 - CVE-2025-43443 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416355 - CVE-2025-43421 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2418576 - CVE-2025-13947 webkit: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop
  • BZ - 2418855 - CVE-2025-43458 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2418857 - CVE-2025-66287 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash

CVEs

  • CVE-2025-13502
  • CVE-2025-13947
  • CVE-2025-43392
  • CVE-2025-43421
  • CVE-2025-43425
  • CVE-2025-43427
  • CVE-2025-43429
  • CVE-2025-43430
  • CVE-2025-43431
  • CVE-2025-43432
  • CVE-2025-43434
  • CVE-2025-43440
  • CVE-2025-43443
  • CVE-2025-43458
  • CVE-2025-66287

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
webkit2gtk3-2.50.3-1.el8_10.src.rpm SHA-256: 0dd07c0e96485823ef93f851bae85ee91e896cad2d71bafafc93928113b914d2
x86_64
webkit2gtk3-2.50.3-1.el8_10.i686.rpm SHA-256: 757b831252f06fd4e81985324945d104fd6334b8b47dc24faaee679319309cdd
webkit2gtk3-2.50.3-1.el8_10.x86_64.rpm SHA-256: f399179a759ca3c9b3698c5a0d99e8036c4761842491b520545617e9c1855bf9
webkit2gtk3-debuginfo-2.50.3-1.el8_10.i686.rpm SHA-256: fe464b92e9d3790628cc0e1b23d1e74fc52fa0046e1cf54984e81524a237d775
webkit2gtk3-debuginfo-2.50.3-1.el8_10.x86_64.rpm SHA-256: 9592b4137076493bc65f98aa8d3da1bafa3a0e8a8d34112d61645bda56c748e7
webkit2gtk3-debugsource-2.50.3-1.el8_10.i686.rpm SHA-256: c035fdebb5510a3e6a5dfd1c8239eb2a66217596e78c525e45181a104b8e99b2
webkit2gtk3-debugsource-2.50.3-1.el8_10.x86_64.rpm SHA-256: e06dbe29af76cf97bf06efc329cf38cad69203964a99b5cc63226bbd34ed0166
webkit2gtk3-devel-2.50.3-1.el8_10.i686.rpm SHA-256: 45467c3d0eb16f8ac875a37fdbfb00b25ea23cba1885d4f9e4a9a5967c3cb6ad
webkit2gtk3-devel-2.50.3-1.el8_10.x86_64.rpm SHA-256: e96685c93e87d7b9089a95aa4194a13595cfda91389910d908953a98ddb63f93
webkit2gtk3-devel-debuginfo-2.50.3-1.el8_10.i686.rpm SHA-256: 65a6c2445a333512be58ecd1fbfec3a4b709851d006848e084578ead4cdda0fe
webkit2gtk3-devel-debuginfo-2.50.3-1.el8_10.x86_64.rpm SHA-256: 79e647a1d73d658edd76fe0e767c04612ae1b4fb1daaf0ca210b78a04763c61b
webkit2gtk3-jsc-2.50.3-1.el8_10.i686.rpm SHA-256: 44e5ac437456bd7a9898d1f24dbc3a57f987c767a4f3567d7c9a2dac5090ac7e
webkit2gtk3-jsc-2.50.3-1.el8_10.x86_64.rpm SHA-256: 65638e34145733c42750a52bcf6665bee6b4ca1abfe1762dca68b71b58a616fa
webkit2gtk3-jsc-debuginfo-2.50.3-1.el8_10.i686.rpm SHA-256: 7866fff3f7eba49b894b91d4eed7167baf4767d867efc10907c32777ebb06c18
webkit2gtk3-jsc-debuginfo-2.50.3-1.el8_10.x86_64.rpm SHA-256: 8b7a963e2b67ca56bc777f140065bc916bb777502752606586ef0285980e82b1
webkit2gtk3-jsc-devel-2.50.3-1.el8_10.i686.rpm SHA-256: bafdece531c5b215e203e687b8bca3f4a9b4bba677e5001244fe8961d278b4a1
webkit2gtk3-jsc-devel-2.50.3-1.el8_10.x86_64.rpm SHA-256: 65aa4edb23feec64f1abc6fe4f56492c3b777abb445017e42b8c8cbdcb74c5bd
webkit2gtk3-jsc-devel-debuginfo-2.50.3-1.el8_10.i686.rpm SHA-256: 1424fb22a1f372f04323209f54e95fd24d3a26b840e20d77b7b4426e9eff467f
webkit2gtk3-jsc-devel-debuginfo-2.50.3-1.el8_10.x86_64.rpm SHA-256: 471f4258d507881998003d3a47a6b6188ffa54a1b096482179890637fe97971c

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
webkit2gtk3-2.50.3-1.el8_10.src.rpm SHA-256: 0dd07c0e96485823ef93f851bae85ee91e896cad2d71bafafc93928113b914d2
s390x
webkit2gtk3-2.50.3-1.el8_10.s390x.rpm SHA-256: 1d44a21e457e302bcc744dfd5e2d501d5ec736b8050bd0192403164c23fe0102
webkit2gtk3-debuginfo-2.50.3-1.el8_10.s390x.rpm SHA-256: 691b6faba1e66ef8f3be2597f99470d79c9282ca925176a6d9cc20c48ec647bd
webkit2gtk3-debugsource-2.50.3-1.el8_10.s390x.rpm SHA-256: ee181e5b68aff5bb0b1b1dbeded975153eb185c02cc75495fadef0d302058fcf
webkit2gtk3-devel-2.50.3-1.el8_10.s390x.rpm SHA-256: 42885a7dd60cb8c4d7c5d067a7f3e4037cb3159b4f6fd89b919ae26939ef2309
webkit2gtk3-devel-debuginfo-2.50.3-1.el8_10.s390x.rpm SHA-256: cbf021eebb83c30395ec9c804ab5a71ff2de0df0347a4e5f5cb4d5db56c53936
webkit2gtk3-jsc-2.50.3-1.el8_10.s390x.rpm SHA-256: 0d6bdc4b6f4be4c472064474410ae60538112ce2f36377cff100b4c35ddb1bfc
webkit2gtk3-jsc-debuginfo-2.50.3-1.el8_10.s390x.rpm SHA-256: 0b219cb18720d693abb27322ce1c72024a241efe12eac58d2050b4f317048204
webkit2gtk3-jsc-devel-2.50.3-1.el8_10.s390x.rpm SHA-256: af513a5239bc7576f31b13da44c5af8bdf75f4ec4e1ae0d11afaaa45ba0f94be
webkit2gtk3-jsc-devel-debuginfo-2.50.3-1.el8_10.s390x.rpm SHA-256: 7f6efc43aba971245340920526542e69ccfd9bf8b292981f0ac66864fd598e3b

Red Hat Enterprise Linux for Power, little endian 8

SRPM
webkit2gtk3-2.50.3-1.el8_10.src.rpm SHA-256: 0dd07c0e96485823ef93f851bae85ee91e896cad2d71bafafc93928113b914d2
ppc64le
webkit2gtk3-2.50.3-1.el8_10.ppc64le.rpm SHA-256: 32d3815a168ac08321fac9de59128674f45b896be2ce40d590d834d763851544
webkit2gtk3-debuginfo-2.50.3-1.el8_10.ppc64le.rpm SHA-256: 5448ec37febb624ff8ad8379fea4d358cda7d49ade17b81930aafe3b2aa2a822
webkit2gtk3-debugsource-2.50.3-1.el8_10.ppc64le.rpm SHA-256: 7d9c5e6a2a605b568fcc0693eeb3a1b8f929fe940a1e4a7f1b66507b15932c2c
webkit2gtk3-devel-2.50.3-1.el8_10.ppc64le.rpm SHA-256: c2be31132324c36302718198fc2f9c15346076e50b70ff5e4e01f629b8635ce4
webkit2gtk3-devel-debuginfo-2.50.3-1.el8_10.ppc64le.rpm SHA-256: 5a81762c77777a06cf477da4bf8e484374428eb43b59d14e1be384784672d13e
webkit2gtk3-jsc-2.50.3-1.el8_10.ppc64le.rpm SHA-256: 1c843de0ae2deb8984ff2d3c500841a93c86ccd1f9483d506769acd68244d7bc
webkit2gtk3-jsc-debuginfo-2.50.3-1.el8_10.ppc64le.rpm SHA-256: a737d0564310b22b44a168b7f757a27e0677c4a1db48d62d90dc0893edb17cc6
webkit2gtk3-jsc-devel-2.50.3-1.el8_10.ppc64le.rpm SHA-256: 15bf207a57f55916e28a2c8a6c19e086f17d83356ed4913854fc8460ec3ed4cd
webkit2gtk3-jsc-devel-debuginfo-2.50.3-1.el8_10.ppc64le.rpm SHA-256: 671b2448dbe64e84c50749a0075f551619d98502dbd71196b063e24d05e9dbd5

Red Hat Enterprise Linux for ARM 64 8

SRPM
webkit2gtk3-2.50.3-1.el8_10.src.rpm SHA-256: 0dd07c0e96485823ef93f851bae85ee91e896cad2d71bafafc93928113b914d2
aarch64
webkit2gtk3-2.50.3-1.el8_10.aarch64.rpm SHA-256: eee471e0f869b45b7fd7ca04fb199425678c995190d737357cb7bd68b014dbac
webkit2gtk3-debuginfo-2.50.3-1.el8_10.aarch64.rpm SHA-256: 8ff1b502509765e07216074653260e53912c4229a79bca8964c3cf73751b5de4
webkit2gtk3-debugsource-2.50.3-1.el8_10.aarch64.rpm SHA-256: 62cb725e4c1a4dcd64ab2f983dad69cc871fa4426266878249df905a55c60ec2
webkit2gtk3-devel-2.50.3-1.el8_10.aarch64.rpm SHA-256: 4db4f97ddc7f165f67199ec958f13c3be9b20acec63af46ae8443bd1068964bd
webkit2gtk3-devel-debuginfo-2.50.3-1.el8_10.aarch64.rpm SHA-256: 5202ef1e3caca923096e4faa234de30df5b6c8151b74bd6ff53486e63824209a
webkit2gtk3-jsc-2.50.3-1.el8_10.aarch64.rpm SHA-256: a38d24b7467b52c202647b317b593c65a7ad8ef0e0d8fc009d24fd09157ab7a2
webkit2gtk3-jsc-debuginfo-2.50.3-1.el8_10.aarch64.rpm SHA-256: 28bfe2c945a27baf6a6ddaabfe26a6f63de55c7c81f9da88fca9678dfeb6297b
webkit2gtk3-jsc-devel-2.50.3-1.el8_10.aarch64.rpm SHA-256: f91a6fd901122efa33c63a87278e38f7ecaccbf327f6fef0e0ed402b8f97c34c
webkit2gtk3-jsc-devel-debuginfo-2.50.3-1.el8_10.aarch64.rpm SHA-256: 7ff3745d02cdc690c95cf62cc7256c10c5d2ff39b6420159d149862254da1f63

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility