UbuntuUpdates.org

Package "webkit2gtk"

Name: webkit2gtk

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • WebKitGTK JavaScript command-line interpreter (transitional dummy package)
  • JavaScript engine library from WebKitGTK - development files
  • JavaScript engine library from WebKitGTK - development files
  • JavaScript engine library from WebKitGTK - command-line interpreter

Latest version: 2.50.2-0ubuntu0.24.04.2
Release: noble (24.04)
Level: security
Repository: universe

Links



Other versions of "webkit2gtk" in Noble

Repository Area Version
base universe 2.44.0-2
base main 2.44.0-2
security main 2.50.2-0ubuntu0.24.04.2
updates main 2.50.2-0ubuntu0.24.04.2
updates universe 2.50.2-0ubuntu0.24.04.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.50.2-0ubuntu0.24.04.2 2025-12-09 20:10:25 UTC

  webkit2gtk (2.50.2-0ubuntu0.24.04.2) noble-security; urgency=medium

  * Update to 2.50.2 to fix security issues.
    - Add patches from resolute package:
      + debian/patches/fix-link-error.patch:
      + debian/patches/fix-crash.patch:
    - CVE-2025-43392, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429,
      CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434,
      CVE-2025-43440, CVE-2025-43443

 -- Marc Deslauriers <email address hidden> Mon, 01 Dec 2025 07:32:52 -0500

Source diff to previous version
CVE-2025-43392 The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. A website may exfiltrate image data cr
CVE-2025-43425 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvO
CVE-2025-43427 This issue was addressed through improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, tvOS 26.1, Safari 26.1, visionOS 26.1. P
CVE-2025-43429 A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted we
CVE-2025-43430 This issue was addressed through improved state management. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1
CVE-2025-43431 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web conten
CVE-2025-43432 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and i
CVE-2025-43434 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously cra
CVE-2025-43440 This issue was addressed with improved checks This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. P
CVE-2025-43443 This issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web content may le

Version: 2.50.1-0ubuntu0.24.04.1 2025-11-27 19:55:41 UTC

  webkit2gtk (2.50.1-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.50.1 to fix security issues.
    - CVE-2025-43343
  * debian/patches, debian/source/lintian-overrides, debian/copyright,
    debian/gbp.conf, debian/*symbols, debian/upstream/*: sync with resolute
    package.
  * debian/control*, debian/rules: switch to building with clang to fix
    FTBFS on i386 and armhf.

 -- Marc Deslauriers <email address hidden> Wed, 29 Oct 2025 09:40:19 -0400

Source diff to previous version
CVE-2025-43343 The issue was addressed with improved memory handling. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. Proc

Version: 2.48.7-0ubuntu0.24.04.2 2025-10-09 21:07:37 UTC

  webkit2gtk (2.48.7-0ubuntu0.24.04.2) noble-security; urgency=medium

  * Update to 2.48.7 to fix security issues.
    - CVE-2025-43272, CVE-2025-43342, CVE-2025-43356, CVE-2025-43368
  * debian/patches/fix-ftbfs-armv7.patch: removed, included in new version.
  * debian/patches/fix-ftbfs-op_instanceof_return_location.patch: fix new
    op_instanceof_return_location build issue.

 -- Marc Deslauriers <email address hidden> Thu, 02 Oct 2025 08:41:44 -0400

Source diff to previous version
CVE-2025-43272 The issue was addressed with improved memory handling. This issue is fixed in Safari 26, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 2
CVE-2025-43342 A correctness issue was addressed with improved checks. This issue is fixed in tvOS 26, Safari 26, iOS 18.7 and iPadOS 18.7, visionOS 26, watchOS 26,
CVE-2025-43356 The issue was addressed with improved handling of caches. This issue is fixed in tvOS 26, Safari 26, iOS 18.7 and iPadOS 18.7, visionOS 26, watchOS 2
CVE-2025-43368 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Process

Version: 2.48.5-0ubuntu0.24.04.1 2025-08-19 21:07:07 UTC

  webkit2gtk (2.48.5-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.48.5 to fix security issues.
    - CVE-2025-6558, CVE-2025-31273, CVE-2025-31278, CVE-2025-43211,
      CVE-2025-43212, CVE-2025-43216, CVE-2025-43227, CVE-2025-43228,
      CVE-2025-43240, CVE-2025-43265
  * debian/patches/fix-ftbfs-armv7.patch:
    - Fix arm build.

 -- Marc Deslauriers <email address hidden> Wed, 13 Aug 2025 14:23:52 -0400

Source diff to previous version
CVE-2025-6558 Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform
CVE-2025-31273 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, macOS Sequoia 15.6, iOS 18.6 and iPadOS 18.6, tvOS 18.6, w
CVE-2025-31278 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iP
CVE-2025-43211 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, macOS Sequoia 15.6, iPadOS 17.7.9, iOS 18.6 and iPadOS 18.
CVE-2025-43212 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, macOS Sequoia 15.6, iOS 18.6 and iPadOS 18.6, tvOS 18.6, w
CVE-2025-43216 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, watchOS 11.6, iOS 18.6 and iPadOS 18.6, iPa
CVE-2025-43227 This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18
CVE-2025-43228 The issue was addressed with improved UI. This issue is fixed in iOS 18.6 and iPadOS 18.6, Safari 18. 6. Visiting a malicious website may lead to add
CVE-2025-43240 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, Safari 18. 6. A download's origin may be incorrectly ass
CVE-2025-43265 An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPad

Version: 2.48.3-0ubuntu0.24.04.1 2025-06-11 20:07:31 UTC

  webkit2gtk (2.48.3-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.48.3 to fix security issues.
    - CVE-2025-24223
    - CVE-2025-31204
    - CVE-2025-31205
    - CVE-2025-31206
    - CVE-2025-31215
    - CVE-2025-31257
  * d/p/fix-typo-denormaldisabler.patch: dropped, no longer needed.

 -- Marc Deslauriers <email address hidden> Wed, 04 Jun 2025 15:28:17 -0400

CVE-2025-24223 The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5,
CVE-2025-31204 The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5,
CVE-2025-31205 The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS
CVE-2025-31206 A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS
CVE-2025-31215 The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia
CVE-2025-31257 This issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5,



About   -   Send Feedback to @ubuntu_updates