Bug 2416355 (CVE-2025-43421)

Summary: CVE-2025-43421 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in WebKitGTK. Processing malicious web content can cause multiple issues in the JIT compiler and result in an unexpected process crash.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2416448, 2416449, 2416451, 2416450, 2416452, 2416453    
Bug Blocks:    

Description OSIDB Bzimport 2025-11-21 15:58:39 UTC
Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

Comment 2 errata-xmlrpc 2025-12-08 01:48:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:22789 https://access.redhat.com/errata/RHSA-2025:22789

Comment 3 errata-xmlrpc 2025-12-08 01:53:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:22790 https://access.redhat.com/errata/RHSA-2025:22790

Comment 4 errata-xmlrpc 2025-12-11 11:34:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2025:23110 https://access.redhat.com/errata/RHSA-2025:23110