stable

webkitgtk-2.48.2-1.fc42

FEDORA-2025-40aeebe6d2 created by catanzaro 10 months ago for Fedora 42
  • Enable CSS Overscroll Behavior by default.
  • Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe.
  • Fix rendering when device scale factor change comes before the web view geometry update.
  • Fix network process crash on exit.
  • Fix several crashes and rendering issues.
  • Fix CVE-2025-24223, CVE-2025-31204, CVE-2025-31205, CVE-2025-31206, CVE-2025-31215, CVE-2025-31257

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2025-40aeebe6d2

This update has been submitted for testing by catanzaro.

10 months ago

This update's test gating status has been changed to 'waiting'.

10 months ago

catanzaro edited this update.

10 months ago

This update has been pushed to testing.

10 months ago

This update's test gating status has been changed to 'passed'.

10 months ago
User Icon bojan commented & provided feedback 10 months ago
karma

Works.

User Icon besser82 commented & provided feedback 10 months ago
karma

Works great! LGTM! =)

This update can be pushed to stable now if the maintainer wishes

10 months ago
User Icon ngompa provided feedback 10 months ago
karma
BZ#2366612 CVE-2025-24223 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all]
BZ#2366614 CVE-2025-31204 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all]
BZ#2366616 CVE-2025-31205 webkitgtk: A malicious website may exfiltrate data cross-origin [fedora-all]
BZ#2366618 CVE-2025-31206 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all]
BZ#2366620 CVE-2025-31215 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all]
BZ#2366622 CVE-2025-31257 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all]

This update has been submitted for stable by bodhi.

10 months ago

This update has been pushed to stable.

10 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
10 months ago
in testing
10 months ago
in stable
10 months ago
modified
10 months ago
approved
10 months ago
BZ#2366612 CVE-2025-24223 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all]
0
1
BZ#2366614 CVE-2025-31204 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all]
0
1
BZ#2366616 CVE-2025-31205 webkitgtk: A malicious website may exfiltrate data cross-origin [fedora-all]
0
1
BZ#2366618 CVE-2025-31206 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all]
0
1
BZ#2366620 CVE-2025-31215 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all]
0
1
BZ#2366622 CVE-2025-31257 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all]
0
1

Automated Test Results