Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23583 - Security Advisory
Issued:
2025-12-18
Updated:
2025-12-18

RHSA-2025:23583 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: webkitgtk4 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for webkitgtk4 is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

WebKitGTK+ is port of the WebKit portable web rendering engine to the GTK+ platform. These packages provide WebKitGTK+ for GTK+ 3.

Security Fix(es):

  • webkit: WebKitGTK / WPE WebKit: Out-of-bounds read and integer underflow vulnerability leading to DoS (CVE-2025-13502)
  • webkitgtk: A website may exfiltrate image data cross-origin (CVE-2025-43392)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43425)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43427)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43429)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43430)
  • webkitgtk: Processing maliciously crafted web content may lead to memory corruption (CVE-2025-43431)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43432)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-43434)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43440)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43443)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43421)
  • webkit: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop (CVE-2025-13947)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-43458)
  • webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-66287)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2416300 - CVE-2025-13502 webkit: WebKitGTK / WPE WebKit: Out-of-bounds read and integer underflow vulnerability leading to DoS
  • BZ - 2416325 - CVE-2025-43392 webkitgtk: A website may exfiltrate image data cross-origin
  • BZ - 2416327 - CVE-2025-43425 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416329 - CVE-2025-43427 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416330 - CVE-2025-43429 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416331 - CVE-2025-43430 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416332 - CVE-2025-43431 webkitgtk: Processing maliciously crafted web content may lead to memory corruption
  • BZ - 2416334 - CVE-2025-43432 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416335 - CVE-2025-43434 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
  • BZ - 2416336 - CVE-2025-43440 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416337 - CVE-2025-43443 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2416355 - CVE-2025-43421 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2418576 - CVE-2025-13947 webkit: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop
  • BZ - 2418855 - CVE-2025-43458 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
  • BZ - 2418857 - CVE-2025-66287 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash

CVEs

  • CVE-2025-13502
  • CVE-2025-13947
  • CVE-2025-43392
  • CVE-2025-43421
  • CVE-2025-43425
  • CVE-2025-43427
  • CVE-2025-43429
  • CVE-2025-43430
  • CVE-2025-43431
  • CVE-2025-43432
  • CVE-2025-43434
  • CVE-2025-43440
  • CVE-2025-43443
  • CVE-2025-43458
  • CVE-2025-66287

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
webkitgtk4-2.50.3-2.el7_9.src.rpm SHA-256: 1d677cb18975f86ab10ff9a0dc56d184b4ee0cbf66bb5b51e8c5be10a7db8e4a
x86_64
webkitgtk4-2.50.3-2.el7_9.x86_64.rpm SHA-256: 6e807845bbfc8095776f36ee23a47d03e71ee42f86d3a647f38804f6a1a301ca
webkitgtk4-debuginfo-2.50.3-2.el7_9.x86_64.rpm SHA-256: 569144eff54943284a628d8accfebf45c595366f62c0f4d1874d3f37964ccc25
webkitgtk4-devel-2.50.3-2.el7_9.x86_64.rpm SHA-256: f8cd774129726b8f35d317592a5bac59e8af03dc9d3ad8e243c593ff486974eb
webkitgtk4-doc-2.50.3-2.el7_9.noarch.rpm SHA-256: 17f966d15ebac29c4b9cc8d3442686a3217d3ced8ec16271553296c21618f6fb
webkitgtk4-jsc-2.50.3-2.el7_9.x86_64.rpm SHA-256: 263383b3dedbefa87cc660dd2aaf3bba107eccb0c6d7356fe64b69673d55710e
webkitgtk4-jsc-devel-2.50.3-2.el7_9.x86_64.rpm SHA-256: f55a8ca76878821f3f3171a890db1c6a78e281b2d57ab23889e66e2a1b1878e9

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
webkitgtk4-2.50.3-2.el7_9.src.rpm SHA-256: 1d677cb18975f86ab10ff9a0dc56d184b4ee0cbf66bb5b51e8c5be10a7db8e4a
s390x
webkitgtk4-2.50.3-2.el7_9.s390x.rpm SHA-256: f24ea503668254521d36c7c4a323e970fbc9ef4d2f37b5f87e12fe9330050c8d
webkitgtk4-debuginfo-2.50.3-2.el7_9.s390x.rpm SHA-256: f49085cb0e056a49b56d7b104dfdfa4fb1382340639eaa32219c811e5e9654d8
webkitgtk4-debuginfo-2.50.3-2.el7_9.s390x.rpm SHA-256: f49085cb0e056a49b56d7b104dfdfa4fb1382340639eaa32219c811e5e9654d8
webkitgtk4-devel-2.50.3-2.el7_9.s390x.rpm SHA-256: a83611fadacca482345fec80535f3ea3c148e4b9009b470bb3d7d9019849a08d
webkitgtk4-doc-2.50.3-2.el7_9.noarch.rpm SHA-256: 17f966d15ebac29c4b9cc8d3442686a3217d3ced8ec16271553296c21618f6fb
webkitgtk4-jsc-2.50.3-2.el7_9.s390x.rpm SHA-256: a928ed3c192ccb294e3fa39360a92d7fd241886916f43e177757c01a45356cd6
webkitgtk4-jsc-devel-2.50.3-2.el7_9.s390x.rpm SHA-256: 8a7e3311bdb6621f01c2c88f69fc17b403e66230e2d94a88bb78fd249fe7877d

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
webkitgtk4-2.50.3-2.el7_9.src.rpm SHA-256: 1d677cb18975f86ab10ff9a0dc56d184b4ee0cbf66bb5b51e8c5be10a7db8e4a
ppc64
webkitgtk4-doc-2.50.3-2.el7_9.noarch.rpm SHA-256: 17f966d15ebac29c4b9cc8d3442686a3217d3ced8ec16271553296c21618f6fb

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
webkitgtk4-2.50.3-2.el7_9.src.rpm SHA-256: 1d677cb18975f86ab10ff9a0dc56d184b4ee0cbf66bb5b51e8c5be10a7db8e4a
ppc64le
webkitgtk4-2.50.3-2.el7_9.ppc64le.rpm SHA-256: bd67c5f63b1e4db01c255ffaeb601e3fb763caa8a864d91d5584b94423ab71e0
webkitgtk4-debuginfo-2.50.3-2.el7_9.ppc64le.rpm SHA-256: 4dc7907e06dc538cfea0b0743f9caa24890479e869bdc30a87881876675b2712
webkitgtk4-devel-2.50.3-2.el7_9.ppc64le.rpm SHA-256: be4e87cf9b7e8c3a6aaadb646714445fda63feb9e7c5a3cfcddf43be46056bd2
webkitgtk4-doc-2.50.3-2.el7_9.noarch.rpm SHA-256: 17f966d15ebac29c4b9cc8d3442686a3217d3ced8ec16271553296c21618f6fb
webkitgtk4-jsc-2.50.3-2.el7_9.ppc64le.rpm SHA-256: a477249740849282b2cd2f21961297c77bd5dc4e137e212f9e290e93b3408ae9
webkitgtk4-jsc-devel-2.50.3-2.el7_9.ppc64le.rpm SHA-256: 196f091d64f4d729e2c5876bef8aa6da211d1e51a19f24c7474ac449664ec92d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility