UbuntuUpdates.org

Package "webkit2gtk"

Name: webkit2gtk

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • WebKitGTK JavaScript command-line interpreter (transitional dummy package)
  • JavaScript engine library from WebKitGTK - command-line interpreter
  • WebKitGTK WebDriver support (transitional dummy package)
  • WebKitGTK WebDriver support

Latest version: 2.52.3-0ubuntu0.25.10.1
Release: questing (25.10)
Level: security
Repository: universe

Links



Other versions of "webkit2gtk" in Questing

Repository Area Version
base main 2.48.6-1ubuntu2
base universe 2.48.6-1ubuntu2
security main 2.52.3-0ubuntu0.25.10.1
updates main 2.52.3-0ubuntu0.25.10.1
updates universe 2.52.3-0ubuntu0.25.10.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.52.3-0ubuntu0.25.10.1 2026-05-06 15:07:47 UTC

  webkit2gtk (2.52.3-0ubuntu0.25.10.1) questing-security; urgency=medium

  * Update to 2.52.3 to fix security issues.
    - debian/libwebkit2gtk-4.0-37.symbols: added new symbols.
    - CVE-2025-43213, CVE-2025-43214, CVE-2025-43457, CVE-2025-43511,
      CVE-2025-46299, CVE-2026-20608, CVE-2026-20635, CVE-2026-20636,
      CVE-2026-20643, CVE-2026-20644, CVE-2026-20652, CVE-2026-20664,
      CVE-2026-20665, CVE-2026-20676, CVE-2026-20691, CVE-2026-28857,
      CVE-2026-28859, CVE-2026-28861, CVE-2026-28871
  * Added some patches from Debian's 2.52.3-2 package (Thanks to Alberto
    Garcia):
    - fix-atomics-detection.patch: Improve detection of whether libatomic
      is required. This was failing in some architectures (armhf, armel)
      with some versions of clang.
    - fix-big-endian-string.patch: Use the native byte order when
      converting from utf8 to utf16. This fixes strings in big-endian
      machine.

 -- Marc Deslauriers <email address hidden> Thu, 23 Apr 2026 08:35:09 -0400

Source diff to previous version
CVE-2025-43213 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, v
CVE-2025-43214 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, v
CVE-2025-43457 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1,
CVE-2025-43511 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.2 and
CVE-2025-46299 A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe
CVE-2026-20608 This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.
CVE-2026-20635 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, ma
CVE-2026-20636 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3.
CVE-2026-20643 A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for
CVE-2026-20644 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, ma
CVE-2026-20652 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, ma
CVE-2026-20664 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4.
CVE-2026-20665 This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.
CVE-2026-20676 This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS
CVE-2026-20691 An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4,
CVE-2026-28857 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4.
CVE-2026-28859 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, vis
CVE-2026-28861 A logic issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.
CVE-2026-28871 A logic issue was addressed with improved checks. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS T

Version: 2.50.4-0ubuntu0.25.10.1 2026-01-13 18:07:51 UTC

  webkit2gtk (2.50.4-0ubuntu0.25.10.1) questing-security; urgency=medium

  * Update to 2.50.4 to fix security issues.
    - CVE-2025-14174, CVE-2025-43501, CVE-2025-43529, CVE-2025-43531,
      CVE-2025-43535, CVE-2025-43536, CVE-2025-43541

 -- Marc Deslauriers <email address hidden> Tue, 06 Jan 2026 08:15:42 -0500

Source diff to previous version
CVE-2025-14174 Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access
CVE-2025-43501 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and i
CVE-2025-43529 A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3,
CVE-2025-43531 A race condition was addressed with improved state handling. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2
CVE-2025-43535 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, ma
CVE-2025-43536 A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Tahoe 26.2, iOS 26.2 and iPadOS 26.2, Safari 26.2,
CVE-2025-43541 A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPa

Version: 2.50.3-0ubuntu0.25.10.1 2026-01-05 16:10:35 UTC

  webkit2gtk (2.50.3-0ubuntu0.25.10.1) questing-security; urgency=medium

  * Update to 2.50.3 to fix security issues.
    - Dropped patches no longer needed:
      + debian/patches/fix-link-error.patch
      + debian/patches/fix-crash.patch
    - CVE-2025-13947
    - CVE-2025-43421
    - CVE-2025-43458
    - CVE-2025-66287

 -- Marc Deslauriers <email address hidden> Tue, 09 Dec 2025 08:33:40 -0500

Source diff to previous version
CVE-2025-13947 A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted
CVE-2025-43421 Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.
CVE-2025-43458 This issue was addressed through improved state management. This issue is fixed in tvOS 26.1, watchOS 26.1, macOS Tahoe 26.1, iOS 26.1 and iPadOS 26.
CVE-2025-66287 A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

Version: 2.50.2-0ubuntu0.25.10.2 2025-12-09 18:32:58 UTC

  webkit2gtk (2.50.2-0ubuntu0.25.10.2) questing-security; urgency=medium

  * Update to 2.50.2 to fix security issues.
    - Add patches from resolute package:
      + debian/patches/fix-link-error.patch:
      + debian/patches/fix-crash.patch:
    - CVE-2025-43392, CVE-2025-43425, CVE-2025-43427, CVE-2025-43429,
      CVE-2025-43430, CVE-2025-43431, CVE-2025-43432, CVE-2025-43434,
      CVE-2025-43440, CVE-2025-43443

 -- Marc Deslauriers <email address hidden> Mon, 01 Dec 2025 07:32:52 -0500

Source diff to previous version
CVE-2025-43392 The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. A website may exfiltrate image data cr
CVE-2025-43425 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvO
CVE-2025-43427 This issue was addressed through improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, tvOS 26.1, Safari 26.1, visionOS 26.1. P
CVE-2025-43429 A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted we
CVE-2025-43430 This issue was addressed through improved state management. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1
CVE-2025-43431 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web conten
CVE-2025-43432 A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and i
CVE-2025-43434 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously cra
CVE-2025-43440 This issue was addressed with improved checks This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. P
CVE-2025-43443 This issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web content may le

Version: 2.50.1-0ubuntu0.25.10.1 2025-11-27 17:41:22 UTC

  webkit2gtk (2.50.1-0ubuntu0.25.10.1) questing-security; urgency=medium

  * Update to 2.50.1 to fix security issues.
    - CVE-2025-43343
  * debian/patches, debian/source/lintian-overrides, debian/copyright,
    debian/gbp.conf, debian/*symbols: sync with resolute package.

 -- Marc Deslauriers <email address hidden> Wed, 29 Oct 2025 09:40:19 -0400

CVE-2025-43343 The issue was addressed with improved memory handling. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. Proc



About   -   Send Feedback to @ubuntu_updates