Fedora Linux 9223 Published by

The Fedora Project has released security updates for several packages. The first update, FEDORA-2025-ac8ed4a110, addresses security vulnerabilities in the tinygltf package on Fedora 42 and updates it to version 2.9.7. Another update, FEDORA-2025-b07cd2cae2, fixes issues with the webkitgtk package on Fedora 43, including CVEs for remote user-assisted information disclosure and unexpected process crashes. The third update, FEDORA-2025-47bff6f74d, is also for the tinygltf package on Fedora 43 but has the same version number as the first update.

Fedora 42 Update: tinygltf-2.9.7-1.fc42
Fedora 43 Update: webkitgtk-2.50.3-1.fc43
Fedora 43 Update: tinygltf-2.9.7-1.fc43




[SECURITY] Fedora 42 Update: tinygltf-2.9.7-1.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-ac8ed4a110
2025-12-07 01:25:53.792333+00:00
--------------------------------------------------------------------------------

Name : tinygltf
Product : Fedora 42
Version : 2.9.7
Release : 1.fc42
URL : https://github.com/syoyo/tinygltf
Summary : Header only C++11 tiny glTF 2.0 library
Description :
TinyGLTF is a header only C++11 glTF 2.0 library.

--------------------------------------------------------------------------------
Update Information:

Update to 2.9.7
--------------------------------------------------------------------------------
ChangeLog:

* Thu Nov 27 2025 Jonathan Steffan [jsteffan@fedoraproject.org] - 2.9.7-1
- Update to 2.9.7 (fedora#2411819)
- Update to 2.9.7
- Fix -devel deps (fedora#2406792)
* Tue Nov 25 2025 Benjamin A. Beasley [code@musicinmybrain.net] - 2.9.6-3
- Rebuilt with latest patched stb_image: memory-safety fixes
* Fri Jul 25 2025 Fedora Release Engineering [releng@fedoraproject.org] - 2.9.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-ac8ed4a110' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 43 Update: webkitgtk-2.50.3-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-b07cd2cae2
2025-12-07 00:55:30.438411+00:00
--------------------------------------------------------------------------------

Name : webkitgtk
Product : Fedora 43
Version : 2.50.3
Release : 1.fc43
URL : https://www.webkitgtk.org/
Summary : GTK web content engine library
Description :
WebKitGTK is the port of the WebKit web rendering engine to the
GTK platform.

--------------------------------------------------------------------------------
Update Information:

Fix seeking and looping of media elements that set the loop property.
Fix several crashes and rendering issues.
Fix CVE-2025-13947, CVE-2025-43458, CVE-2025-66287
--------------------------------------------------------------------------------
ChangeLog:

* Thu Dec 4 2025 Michael Catanzaro [mcatanzaro@redhat.com] - 2.50.3-1
- Update to 2.50.3
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2418581 - CVE-2025-13947 webkitgtk: WebKitGTK: Remote user-assisted information disclosure via file drag-and-drop [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2418581
[ 2 ] Bug #2418863 - CVE-2025-43458 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2418863
[ 3 ] Bug #2418867 - CVE-2025-66287 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2418867
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-b07cd2cae2' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 43 Update: tinygltf-2.9.7-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-47bff6f74d
2025-12-07 00:55:30.438322+00:00
--------------------------------------------------------------------------------

Name : tinygltf
Product : Fedora 43
Version : 2.9.7
Release : 1.fc43
URL : https://github.com/syoyo/tinygltf
Summary : Header only C++11 tiny glTF 2.0 library
Description :
TinyGLTF is a header only C++11 glTF 2.0 library.

--------------------------------------------------------------------------------
Update Information:

Update to 2.9.7
--------------------------------------------------------------------------------
ChangeLog:

* Thu Nov 27 2025 Jonathan Steffan [jsteffan@fedoraproject.org] - 2.9.7-1
- Update to 2.9.7 (fedora#2411819)
- Update to 2.9.7
- Fix -devel deps (fedora#2406792)
* Tue Nov 25 2025 Benjamin A. Beasley [code@musicinmybrain.net] - 2.9.6-3
- Rebuilt with latest patched stb_image: memory-safety fixes
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-47bff6f74d' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--