AVG-2865 log

Package webkit2gtk-4.1
Status Vulnerable
Severity High
Type multiple issues
Affected 2.48.2-1
Fixed 2.49.1-1
Current 2.48.2-1 [extra]
Ticket Create
Created Sun May 18 00:57:25 2025
Issue Severity Remote Type Description
CVE-2025-31257 High Yes Denial of service
Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in an unexpected crash.
CVE-2025-31215 Medium Yes Denial of service
Processing malicious web content can cause a NULL pointer dereference due to improper checks, resulting in an unexpected process crash.
CVE-2025-31206 High Yes Denial of service
Processing malicious web content can cause a type confusion issue due to improper state handling and result in an unexpected crash.
CVE-2025-31205 High Yes Information disclosure
A malicious website may steal data cross-origin due to improper security checks within the web browser or rendering engine, leading to unauthorized...
CVE-2025-31204 High Yes Insufficient validation
Processing malicious web content can cause out-of-bounds memory access due to improper memory handling and result in memory corruption.
CVE-2025-24223 High Yes Incorrect calculation
Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
References
https://webkitgtk.org/security/WSA-2025-0004.html
https://wpewebkit.org/security/WSA-2025-0004.html