Advisories ยป MGASA-2025-0325

Updated webkit2 packages fix security vulnerabilities

Publication date: 09 Dec 2025
Modification date: 09 Dec 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-13947 , CVE-2025-43421 , CVE-2025-43458 , CVE-2025-66287

Description

A website may be able to exfiltrate sensitive system information.
Description: The issue was addressed through improved state checks -
CVE-2025-13947.
Processing maliciously crafted web content may lead to an unexpected
process crash. Description: Multiple issues were addressed by disabling
array allocation sinking - CVE-2025-43421.
Processing maliciously crafted web content may lead to an unexpected
process crash. Description: This issue was addressed through improved
state management - CVE-2025-43458.
Processing maliciously crafted web content may lead to an unexpected
process crash. Description: The issue was addressed with improved memory
handling - CVE-2025-66287.
                

References

SRPMS

9/core