Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

openSUSE webkit2gtk3 Important Update Security Advisory 2026-21129-1

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
Critical openSUSE update resolving 16 issues in webkit2gtk3; essential fixes for improved security and performance.
An update that solves 16 vulnerabilities and has 16 bug fixes can now be installed.

Description

This update for webkit2gtk3 fixes the following issues

Update to version 2.52.4:

- CVE-2026-28847: processing maliciously crafted web content may lead to an unexpected process crash or arbitrary code

execution due to a heap buffer overflow (bsc#1267506).

- CVE-2026-28883: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after-

free issue (bsc#1267507).

- CVE-2026-28901: processing maliciously crafted web content may lead to an unexpected process crash due to improper

memory handling (bsc#1267508).

- CVE-2026-28902: processing maliciously crafted web content may lead to an unexpected process crash due to improper

memory handling (bsc#1267509).

- CVE-2026-28903: processing maliciously crafted web content may lead to an unexpected process crash due to improper

memory handling (bsc#1267510).

- CVE-2026-28904: processing maliciously crafted web content may lead to an unexpected process crash due to improper

memory handling...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

WebKitGTK-4.0-lang-2.52.4-160000.1.1

WebKitGTK-4.1-lang-2.52.4-160000.1.1

WebKitGTK-6.0-lang-2.52.4-160000.1.1

libjavascriptcoregtk-4_0-18-2.52.4-160000.1.1

libjavascriptcoregtk-4_1-0-2.52.4-160000.1.1

libjavascriptcoregtk-6_0-1-2.52.4-160000.1.1

libwebkit2gtk-4_0-37-2.52.4-160000.1.1

libwebkit2gtk-4_1-0-2.52.4-160000.1.1

libwebkitgtk-6_0-4-2.52.4-160000.1.1

typelib-1_0-JavaScriptCore-4_0-2.52.4-160000.1.1

typelib-1_0-JavaScriptCore-4_1-2.52.4-160000.1.1

typelib-1_0-JavaScriptCore-6_0-2.52.4-160000.1.1

typelib-1_0-WebKit-6_0-2.52.4-160000.1.1

typelib-1_0-WebKit2-4_0-2.52.4-160000.1.1

typelib-1_0-WebKit2-4_1-2.52.4-160000.1.1

typelib-1_0-WebKit2WebExtension-4_0-2.52.4-160000.1.1

typelib-1_0-WebKit2WebExtension-4_1-2.52.4-160000.1.1

typelib-1_0-WebKitWebProcessExtension-6_0-2.52.4-160000.1.1

webkit-jsc-4-2.52.4-160000.1.1

webkit-jsc-4.1-2.52.4-160000.1.1

webkit-jsc-6.0-2.52.4-160000.1.1

webkit2gtk-4_0-injected-bundles-2.52.4-160000.1.1

webkit2gtk-4_1-injected-bundles-2.52.4-160000.1.1

webk...

Read the Full Advisory

References

* bsc#1267506

* bsc#1267507

* bsc#1267508

* bsc#1267509

* bsc#1267510

* bsc#1267511

* bsc#1267512

* bsc#1267513

* bsc#1267514

* bsc#1267515

* bsc#1267516

* bsc#1267517

* bsc#1267518

* bsc#1267519

* bsc#1267520

* bsc#1267521

References:

* https://www.suse.com/security/cve/CVE-2026-28847.html

* https://www.suse.com/security/cve/CVE-2026-28883.html

* https://www.suse.com/security/cve/CVE-2026-28901.html

* https://www.suse.com/security/cve/CVE-2026-28902.html

* https://www.suse.com/security/cve/CVE-2026-28903.html

* https://www.suse.com/security/cve/CVE-2026-28904.html

* https://www.suse.com/security/cve/CVE-2026-28905.html

* https://www.suse.com/security/cve/CVE-2026-28907.html

* https://www.suse.com/security/cve/CVE-2026-28942.html

* https://www.suse.com/security/cve/CVE-2026-28946.html

* https://www.suse.com/security/cve/CVE-2026-28947.html

* https://www.suse.com/security/cve/CVE-2026-28953.html

* https://www.suse.com/security/cve/CVE-2026-28955.html

* https://www.suse.com/security/cve/CVE-2026-28958.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21129-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here