Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
Google Chrome and Firefox may crash or leak memory on Linux
published 10 months ago
Summary
An update is available for the webkit2gtk3 library, which is used by Google Chrome and Firefox on Linux. If not updated, these browsers may crash or leak sensitive information. Update your Linux system and web browsers to a version that includes this fix.
What to do
- Update redhat webkit2gtk3 to version 0:2.50.0-2.el9_4.
- Update redhat webkit2gtk3-debuginfo to version 0:2.50.0-2.el9_4.
- Update redhat webkit2gtk3-debugsource to version 0:2.50.0-2.el9_4.
- Update redhat webkit2gtk3-devel to version 0:2.50.0-2.el9_4.
- Update redhat webkit2gtk3-devel-debuginfo to version 0:2.50.0-2.el9_4.
- Update redhat webkit2gtk3-jsc to version 0:2.50.0-2.el9_4.
- Update redhat webkit2gtk3-jsc-debuginfo to version 0:2.50.0-2.el9_4.
- Update redhat webkit2gtk3-jsc-devel to version 0:2.50.0-2.el9_4.
- Update redhat webkit2gtk3-jsc-devel-debuginfo to version 0:2.50.0-2.el9_4.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3 |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3-debuginfo |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3-debugsource |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3-devel |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3-devel-debuginfo |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3-jsc |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3-jsc-debuginfo |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3-jsc-devel |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
| Red Hat:rhel_eus:9.4::appstream | redhat | webkit2gtk3-jsc-devel-debuginfo |
< 0:2.50.0-2.el9_4 Fix: upgrade to 0:2.50.0-2.el9_4
|
Original advisory text
Red Hat Security Advisory: webkit2gtk3 security update
References
- https://www.cve.org/CVERecord?id=CVE-2025-31223 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2025:17741 Vendor Advisory
- https://access.redhat.com/security/updates/classification/#important Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2397626 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2397627 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2397628 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2397630 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_17741.... Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2025-31223 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2448779 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-31223 Vendor Advisory
- https://webkitgtk.org/security/WSA-2026-0001.html Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-31277 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2448780 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-31277 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-31277 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-43272 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-43272 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-43272 Vendor Advisory
- https://webkitgtk.org/security/WSA-2025-0006.html Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-43342 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-43342 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-43342 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2025-43356 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-43356 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-43356 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2025-43368 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-43368 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-43368 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2025-43419 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2416326 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-43419 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-43419 Vendor Advisory
- https://webkitgtk.org/security/WSA-2025-0008.html Third Party Advisory
Severity
8.8
High
CVSS 3.1: 8.8 (OSV)
Timeline
Published13 Oct 2025
Updated21 Mar 2026
First seen21 Mar 2026
Sources
RHSA-2025:17741 · OSV
Monitor software like this
Free during beta