webkit2gtk3-2.48.1-1.el8_10.ML.1

エラータID: AXSA:2025-9884:08

リリース日: 
2025/04/25 Friday - 10:57
題名: 
webkit2gtk3-2.48.1-1.el8_10.ML.1
影響のあるチャネル: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-44192)
* webkitgtk: A malicious website may exfiltrate data cross-origin (CVE-2024-54467)
* webkitgtk: Processing web content may lead to a denial-of-service (CVE-2024-54551)
* webkitgtk: Loading a malicious iframe may lead to a cross-site scripting attack (CVE-2025-24208)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-24209)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-24216)
* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-30427)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-44192
The issue was addressed with improved checks. This issue is fixed in watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2024-54467
A cookie management issue was addressed with improved state management. This issue is fixed in watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.
CVE-2024-54551
The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.6, tvOS 17.6, Safari 17.6, macOS Sonoma 14.6, visionOS 1.3, iOS 17.6 and iPadOS 17.6. Processing web content may lead to a denial-of-service.
CVE-2025-24208
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
CVE-2025-24209
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-24216
The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
CVE-2025-30427
A use-after-free issue was addressed with improved memory management. This issue is fixed in visionOS 2.4, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, Safari 18.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. webkit2gtk3-2.48.1-1.el8_10.ML.1.src.rpm
    MD5: 9a7d0013da2d753264cf06397c71bef8
    SHA-256: e1416a67650c60688af32442dc234567274845d273bbb63573f37644f63d5457
    Size: 42.19 MB

Asianux Server 8 for x86_64
  1. webkit2gtk3-2.48.1-1.el8_10.ML.1.i686.rpm
    MD5: 11032038a29ccbab544990381ffb7d7c
    SHA-256: 117220397992a8934b33e0c32e384199a1c88be5f1e11443c63af7283eba72f8
    Size: 26.55 MB
  2. webkit2gtk3-2.48.1-1.el8_10.ML.1.x86_64.rpm
    MD5: 8a3bb37d2b89f3876d0e8759a4bc2158
    SHA-256: 67982218cbdb5df615d157c0be8f62e75492ad8d78487202b343d17b414a6e82
    Size: 26.42 MB
  3. webkit2gtk3-devel-2.48.1-1.el8_10.ML.1.i686.rpm
    MD5: d7f11935dd56be58fea02f0211164e5c
    SHA-256: 22c43db523c10d478dd31db1c937196b4c0f915428888c6fe69392030e7d783b
    Size: 307.34 kB
  4. webkit2gtk3-devel-2.48.1-1.el8_10.ML.1.x86_64.rpm
    MD5: da2f847fa794ce6b44d05af2ffa9d331
    SHA-256: 1c3411f422917b325fb8160a46318829b31a74f3309f2557aee83e69e36cac3b
    Size: 308.88 kB
  5. webkit2gtk3-jsc-2.48.1-1.el8_10.ML.1.i686.rpm
    MD5: e40ec2a0309d77294ba63207b6158fca
    SHA-256: 8d70669c4f81ce2e1c028d77e12bfd73841aa96cbd8d1b74916c1abc3d23c9e7
    Size: 3.88 MB
  6. webkit2gtk3-jsc-2.48.1-1.el8_10.ML.1.x86_64.rpm
    MD5: 8ce1ee465c1d13661779936eff3773fd
    SHA-256: 0704562b249c679ee78918444c25e90f2671619f86df79df8ec3ecc9bcbec9a5
    Size: 4.32 MB
  7. webkit2gtk3-jsc-devel-2.48.1-1.el8_10.ML.1.i686.rpm
    MD5: 44b921db655bce900527a8228af8faa0
    SHA-256: ccdea549c153e5e85005395628c3849ee1b2bc66d1215d29dbee78d3a6a9c2d7
    Size: 165.41 kB
  8. webkit2gtk3-jsc-devel-2.48.1-1.el8_10.ML.1.x86_64.rpm
    MD5: ce9cd80c664e4ce06d92a7a3c2707858
    SHA-256: f76b97df693fff6c41eea9cf8d3c12aa7c2be7c23a5e0b3dab4b03bd1aa5ca59
    Size: 159.34 kB