Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 569
Alerts This Week
Warning Icon 1 569

openSUSE WebKit2GTK3 Important Memory Corruption Process Crash 2026-3338-1

opensuse
Calendar Grey July 28, 2026
Scroller Opensuse
The update addresses important vulnerabilities in webkit2gtk3 that can allow memory corruption and process crashes. Install now!
SUSE has released an important security update for webkit2gtk3, addressing 23 vulnerabilities, including issues with memory corruption, process crashes, and data leakage in affecte...

Description

This update for webkit2gtk3 fixes the following issues:

* CVE-2024-4367: missing type check when handling fonts in PDF.js can allow

arbitrary JavaScript execution (bsc#1271638).

* CVE-2026-39872: maliciously crafted web content can lead to an unexpected

process crash (bsc#1271638).

* CVE-2026-43663: maliciously crafted web content can lead to an unexpected

process crash (bsc#1271638).

* CVE-2026-43676: out-of-bounds access when processing web content can lead to

an unexpected Safari crash (bsc#1271638).

* CVE-2026-43699: use-after-free issue when processing web content can lead to

an unexpected process crash (bsc#1271638).

* CVE-2026-43701: malicious website can process restricted web content outside

the sandbox (bsc#1271638).

* CVE-2026-43705: type confusion issue when processing web content can lead to

memory corruption (bsc#1271638).

* CVE-2026-43707: memory corruption issue when processing web content can lead

to an unexpected...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* Development Tools Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3338=1

* Basesystem Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3338=1

* Desktop Applications Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3338=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3338=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3338=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-3338=1

Package List

* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)

* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1

* webkit2gtk4-debugsource-2.52.5-150600.12.71.1

* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1

* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1

* webkit2gtk4-devel-2.52.5-150600.12.71.1

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)

* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1

* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1

* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1

* webkit2gtk3-debugsource-2.52.5-150600.12.71.1

* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1

* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1

* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1

* webkit2gtk4-devel-2.52.5-150600.12.71.1

* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1

* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1

*...

Read the Full Advisory

References

* bsc#1271638

## References:

* https://www.suse.com/security/cve/CVE-2024-4367.html

* https://www.suse.com/security/cve/CVE-2026-39872.html

* https://www.suse.com/security/cve/CVE-2026-43663.html

* https://www.suse.com/security/cve/CVE-2026-43676.html

* https://www.suse.com/security/cve/CVE-2026-43699.html

* https://www.suse.com/security/cve/CVE-2026-43701.html

* https://www.suse.com/security/cve/CVE-2026-43705.html

* https://www.suse.com/security/cve/CVE-2026-43707.html

* https://www.suse.com/security/cve/CVE-2026-43712.html

* https://www.suse.com/security/cve/CVE-2026-43713.html

* https://www.suse.com/security/cve/CVE-2026-43715.html

* https://www.suse.com/security/cve/CVE-2026-43716.html

* https://www.suse.com/security/cve/CVE-2026-43720.html

* https://www.suse.com/security/cve/CVE-2026-43721.html

* https://www.suse.com/security/cve/CVE-2026-43725.html

* https://www.suse.com/security/cve/CVE-2026-43726.html

* https://www.suse.com/security/cve/CVE-2026-43727.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3338-1
Release Date: 2026-07-28T09:55:09Z

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.