Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for webkit2gtk3 fixes the following issues:
* CVE-2024-4367: missing type check when handling fonts in PDF.js can allow
arbitrary JavaScript execution (bsc#1271638).
* CVE-2026-39872: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43663: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43676: out-of-bounds access when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43699: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43701: malicious website can process restricted web content outside
the sandbox (bsc#1271638).
* CVE-2026-43705: type confusion issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43707: memory corruption issue when processing web content can lead
to an unexpected...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3338=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3338=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3338=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3338=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3338=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3338=1
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
*...
Read the Full Advisory* bsc#1271638
## References:
* https://www.suse.com/security/cve/CVE-2024-4367.html
* https://www.suse.com/security/cve/CVE-2026-39872.html
* https://www.suse.com/security/cve/CVE-2026-43663.html
* https://www.suse.com/security/cve/CVE-2026-43676.html
* https://www.suse.com/security/cve/CVE-2026-43699.html
* https://www.suse.com/security/cve/CVE-2026-43701.html
* https://www.suse.com/security/cve/CVE-2026-43705.html
* https://www.suse.com/security/cve/CVE-2026-43707.html
* https://www.suse.com/security/cve/CVE-2026-43712.html
* https://www.suse.com/security/cve/CVE-2026-43713.html
* https://www.suse.com/security/cve/CVE-2026-43715.html
* https://www.suse.com/security/cve/CVE-2026-43716.html
* https://www.suse.com/security/cve/CVE-2026-43720.html
* https://www.suse.com/security/cve/CVE-2026-43721.html
* https://www.suse.com/security/cve/CVE-2026-43725.html
* https://www.suse.com/security/cve/CVE-2026-43726.html
* https://www.suse.com/security/cve/CVE-2026-43727.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.