RHSA-2025:8541: Important: webkit2gtk3 security update
Important: webkit2gtk3 security update
Other sources
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.Security Fix(es): webkitgtk: A malicious website may exfiltrate data cross-origin (CVE-2025-31205) webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-31257)For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8541?
The severity of RHSA-2025:8541 is classified as important.
How do I fix RHSA-2025:8541?
To fix RHSA-2025:8541, update webkit2gtk3 to version 2.48.2-1.el8_6.
What vulnerabilities are addressed by RHSA-2025:8541?
RHSA-2025:8541 addresses vulnerabilities including CVE-2025-31205, allowing malicious websites to exfiltrate data cross-origin.
Which products are affected by RHSA-2025:8541?
Affected products include Red Hat Enterprise Linux Server, Red Hat Enterprise Linux for SAP Solutions, and various webkit2gtk3 packages.
What does the webkit2gtk3 update in RHSA-2025:8541 entail?
The webkit2gtk3 update in RHSA-2025:8541 includes security fixes to mitigate cross-origin data exfiltration risks.