Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: webkit2gtk3 Important Memory Corruption Fix Vuln 2025:02973-1

suse
Calendar Grey August 25, 2025
Dist Suse Esm H88
Vital patch for webkit2gtk3 released, targeting various vulnerabilities to enhance system protection against potential threats.
* bsc#1239547 * bsc#1239863 * bsc#1239864 * bsc#1247562 * bsc#1247563

Summary

## This update for webkit2gtk3 fixes the following issues: * Update to version 2.48.5: * CVE-2025-31273: Fixed processing maliciously crafted web content leading to memory corruption (bsc#1247564) * CVE-2025-43265: Fixed processing maliciously crafted web content disclosing internal states of the app (bsc#1247600) * CVE-2025-43216: Fixed processing maliciously crafted web content leading to an unexpected Safari crash (bsc#1247596) * CVE-2025-31278: Fixed processing maliciously crafted web content leading to memory corruption (bsc#1247563) * CVE-2025-6558: Fixed processing maliciously crafted web content leading to an unexpected Safari crash. (bsc#1247742) * CVE-2025-43227: Fixed Processing maliciously crafted web content disclosing sensitive user information (bsc#1247597)

References

* bsc#1239547

* bsc#1239863

* bsc#1239864

* bsc#1247562

* bsc#1247563

* bsc#1247564

* bsc#1247565

* bsc#1247595

* bsc#1247596

* bsc#1247597

* bsc#1247598

* bsc#1247599

* bsc#1247600

* bsc#1247742

Cross-

* CVE-2024-44192

* CVE-2024-54467

* CVE-2025-24189

* CVE-2025-24201

* CVE-2025-31273

* CVE-2025-31278

* CVE-2025-43211

* CVE-2025-43212

* CVE-2025-43216

* CVE-2025-43227

* CVE-2025-43228

* CVE-2025-43240

* CVE-2025-43265

* CVE-2025-6558

CVSS scores:

* CVE-2024-44192 ( SUSE ): 7.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2024-44192 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-44192 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-44192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:02973-1
Release Date: 2025-08-25T08:49:20Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here