Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
It was discovered that beets, a media library management system, is vulnerable to run arbitrary JavaScript code in the victim browser, exfiltrate viewable data, and perform UI-driven actions as the victim session. For Debian 11 bullseye, this problem has been fixed in version. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4641-1
A vulnerability was discovered in yelp, the GNOME help browser, that allows a crafted help document to read files accessible to the user and exfiltrate them to a remote server through resources loaded by the embedded web view. When yelp is launched from a sandboxed application (for example via the Flatpak OpenURI portal), this also enables a. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6319-1
External DNS requests from 'internal' networks could lead to data exfiltration - CVE-2024-29018 We can't determine if docker 24.0.5 is affected but as it is no longer supported we are releasing version 25.0.7, as it is supported and free of the CVE. . MGASA-2025-0189 - Updated docker packages fix security vulnerability Publication date: 24 Jun 2025 URL: https://advisories.mageia.org/MGASA-2025-0189.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-29018 External DNS requests from 'internal' networks could lead to data exfiltration - CVE-2024-29018 We can't determine if docker 24.0.5 is affected but as it is no longer supported we are releasing version 25.0.7, as it is supported and free of the CVE. References: - https://bugs.mageia.org/show_bug.cgi?id=33870 - External DNS requests from 'internal' networks could lead to data - https://github.com/moby/moby/security/advisories/GHSA-mq39-4gv4-mvpx - https://github.com/moby/moby/releases/tag/v25.0.7 - https://www.cve.org/CVERecord?id=CVE-2024-29018 SRPMS: - 9/core/docker-25.0.7-1.mga9 . Remote DNS queries may leak sensitive information; upgrade Docker to address vulnerabilities linked to CVE-2024-29018.. Docker, Mageia, Data Exfiltration, Security Update, CVE-2024-29018. . Severity: Important. LinuxSecurity.com Team
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-24223 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5937-1
* bsc#1223409 * bsc#1234089 * bsc#1237335 * bsc#1237367 * bsc#1239185 . # Security update for docker Announcement ID: SUSE-SU-2025:20205-1 Release Date: 2025-04-24T14:58:45Z Rating: important References: * bsc#1223409 * bsc#1234089 * bsc#1237335 * bsc#1237367 * bsc#1239185 * bsc#1239322 * bsc#1239765 * jsc#PED-12534 * jsc#PED-8905 Cross-References: * CVE-2024-29018 * CVE-2025-0495 * CVE-2025-22868 * CVE-2025-22869 CVSS scores: * CVE-2024-29018 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-29018 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-29018 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-29018 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-0495 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-0495 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N * CVE-2025-0495 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-22868 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22868 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities, contains two features and has three fixes can now be installed. ## Description: This update for docker fixes the following issues: * Updated to docker-buildx v0.22.0. * Updated to Docker 27.5.1-ce. * CVE-2025-0495:buildx: Fixed credential leakage to telemetry endpoints (bsc#1239765) * CVE-2025-22868: Fixed golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185) * CVE-2025-22869: Fixed golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). * CVE-2024-29018:moby: external DNS requests from 'internal' networks could lead to data exfiltration (bsc#1234089) * Make container-selinux requirement conditional on selinux-policy (bsc#1237367) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-301=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * docker-buildx-0.22.0-2.1 * docker-buildx-debuginfo-0.22.0-2.1 * docker-27.5.1_ce-2.1 * docker-debuginfo-27.5.1_ce-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-29018.html * https://www.suse.com/security/cve/CVE-2025-0495.html * https://www.suse.com/security/cve/CVE-2025-22868.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://bugzilla.suse.com/show_bug.cgi?id=1223409 * https://bugzilla.suse.com/show_bug.cgi?id=1234089 * https://bugzilla.suse.com/show_bug.cgi?id=1237335 * https://bugzilla.suse.com/show_bug.cgi?id=1237367 * https://bugzilla.suse.com/show_bug.cgi?id=1239185 * https://bugzilla.suse.com/show_bug.cgi?id=1239322 * https://bugzilla.suse.com/show_bug.cgi?id=1239765 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-12534&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-8905&page_caps=&user_role= . This notification highlights essential Docker updates for SUSE, aimed at mitigating various vulnerabilities, resolving ongoingissues, and improving overall security.. SUSE Docker Updates, Container Security Patches, SUSE Security Fixes. . Severity: Important. LinuxSecurity.com Team
* bsc#1223409 * bsc#1234089 * bsc#1237335 * bsc#1237367 * bsc#1239185 . # Security update for docker Announcement ID: SUSE-SU-2025:20205-1 Release Date: 2025-04-24T14:58:45Z Rating: important References: * bsc#1223409 * bsc#1234089 * bsc#1237335 * bsc#1237367 * bsc#1239185 * bsc#1239322 * bsc#1239765 * jsc#PED-12534 * jsc#PED-8905 Cross-References: * CVE-2024-29018 * CVE-2025-0495 * CVE-2025-22868 * CVE-2025-22869 CVSS scores: * CVE-2024-29018 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-29018 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-29018 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-29018 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-0495 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-0495 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N * CVE-2025-0495 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-22868 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22868 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities, contains two features and has three fixes can now be installed. ## Description: This update for docker fixes the following issues: * Updated to docker-buildx v0.22.0. * Updated to Docker 27.5.1-ce. * CVE-2025-0495:buildx: Fixed credential leakage to telemetry endpoints (bsc#1239765) * CVE-2025-22868: Fixed golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185) * CVE-2025-22869: Fixed golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). * CVE-2024-29018:moby: external DNS requests from 'internal' networks could lead to data exfiltration (bsc#1234089) * Make container-selinux requirement conditional on selinux-policy (bsc#1237367) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-301=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * docker-buildx-debuginfo-0.22.0-2.1 * docker-buildx-0.22.0-2.1 * docker-debuginfo-27.5.1_ce-2.1 * docker-27.5.1_ce-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-29018.html * https://www.suse.com/security/cve/CVE-2025-0495.html * https://www.suse.com/security/cve/CVE-2025-22868.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://bugzilla.suse.com/show_bug.cgi?id=1223409 * https://bugzilla.suse.com/show_bug.cgi?id=1234089 * https://bugzilla.suse.com/show_bug.cgi?id=1237335 * https://bugzilla.suse.com/show_bug.cgi?id=1237367 * https://bugzilla.suse.com/show_bug.cgi?id=1239185 * https://bugzilla.suse.com/show_bug.cgi?id=1239322 * https://bugzilla.suse.com/show_bug.cgi?id=1239765 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-12534&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-8905&page_caps=&user_role= . SUSE Docker's critical update tackles major vulnerabilities, boosting security and performance with various fixes for users.. SUSESecurity, Docker Update, Cybersecurity Patch, Vulnerability Management. . Severity: Critical. LinuxSecurity.com Team
* bsc#1222905 * bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 . # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2025:01746-1 Release Date: 2025-05-29T12:38:02Z Rating: important References: * bsc#1222905 * bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288 * bsc#1243289 * bsc#1243424 * bsc#1243596 Cross-References: * CVE-2023-42875 * CVE-2023-42970 * CVE-2024-23226 * CVE-2025-24223 * CVE-2025-31204 * CVE-2025-31205 * CVE-2025-31206 * CVE-2025-31215 * CVE-2025-31257 CVSS scores: * CVE-2023-42875 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2023-42875 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2023-42875 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2023-42970 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-42970 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-42970 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-23226 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-23226 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-23226 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24223 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-24223 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24223 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-31204 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-31204 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-31205 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-31205 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-31206 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-31206 ( NVD ): 4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-31215 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-31215 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-31257 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-31257 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-31257 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP6 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: Update to version 2.48.2. Security issues fixed: * CVE-2025-31205: lack of checks may lead to cross-origin data exfiltration through a malicious website (bsc#1243282). * CVE-2025-31204: improper memory handling when processing certain web content may lead to memory corruption (bsc#1243286). * CVE-2025-31206: type confusion issue when processing certain web content may lead to an unexpected crash (bsc#1243288). * CVE-2025-31215: lack of checks when processing certain web content may lead to an unexpected crash (bsc#1243289). * CVE-2025-31257: improper memory handling when processing certain web content may lead to an unexpected crash (bsc#1243596). * CVE-2025-24223: improper memory handling when processing certain web content may lead to memory corruption(bsc#1243424). Other changes and issues fixed: * Enable CSS overscroll behavior by default. * Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. * Fix rendering when device scale factor change comes before the web view geometry update. * Fix network process crash on exit. * Fix the build with ENABLE_RESOURCE_USAGE=OFF. * Fix several crashes and rendering issues. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1746=1 openSUSE-SLE-15.6-2025-1746=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1746=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-1746=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1746=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1746=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-1746=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-1746=1 ## Package List: * openSUSE Leap 15.6 (noarch) * WebKitGTK-4.1-lang-2.48.2-150600.12.40.2 * WebKitGTK-4.0-lang-2.48.2-150600.12.40.2 * WebKitGTK-6.0-lang-2.48.2-150600.12.40.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * webkit2gtk-4_1-injected-bundles-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-minibrowser-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_1-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_0-2.48.2-150600.12.40.2 *typelib-1_0-WebKit2-4_0-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-2.48.2-150600.12.40.2 * webkit-jsc-6.0-2.48.2-150600.12.40.2 * webkit2gtk3-devel-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-minibrowser-debuginfo-2.48.2-150600.12.40.2 * webkit-jsc-4-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * webkit-jsc-6.0-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_1-2.48.2-150600.12.40.2 * webkit2gtk4-minibrowser-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * webkit-jsc-4-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-debugsource-2.48.2-150600.12.40.2 * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-minibrowser-2.48.2-150600.12.40.2 * webkit2gtk3-minibrowser-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-6_0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-minibrowser-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_1-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-2.48.2-150600.12.40.2 * webkit-jsc-4.1-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-devel-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-2.48.2-150600.12.40.2 * webkit-jsc-4.1-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk4-devel-2.48.2-150600.12.40.2 *webkit2gtk3-soup2-debugsource-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 * openSUSE Leap 15.6 (x86_64) * libjavascriptcoregtk-4_1-0-32bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-32bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-32bit-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-32bit-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.48.2-150600.12.40.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libjavascriptcoregtk-4_1-0-64bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-64bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-64bit-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-64bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.48.2-150600.12.40.2 * Basesystem Module 15-SP6 (noarch) * WebKitGTK-4.0-lang-2.48.2-150600.12.40.2 * WebKitGTK-6.0-lang-2.48.2-150600.12.40.2 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-4_0-18-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-devel-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_0-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_0-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-2.48.2-150600.12.40.2 *libjavascriptcoregtk-4_0-18-debuginfo-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-debugsource-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_0-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 * Basesystem Module 15-SP7 (noarch) * WebKitGTK-4.0-lang-2.48.2-150600.12.40.2 * WebKitGTK-6.0-lang-2.48.2-150600.12.40.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-4_0-18-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-devel-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_0-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_0-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-debugsource-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_0-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 * Desktop Applications Module 15-SP6 (noarch) * WebKitGTK-4.1-lang-2.48.2-150600.12.40.2 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * webkit2gtk-4_1-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.2-150600.12.40.2 *libwebkit2gtk-4_1-0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_1-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-debugsource-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_1-2.48.2-150600.12.40.2 * webkit2gtk3-devel-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_1-2.48.2-150600.12.40.2 * Desktop Applications Module 15-SP7 (noarch) * WebKitGTK-4.1-lang-2.48.2-150600.12.40.2 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * webkit2gtk-4_1-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_1-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-debugsource-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_1-2.48.2-150600.12.40.2 * webkit2gtk3-devel-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_1-2.48.2-150600.12.40.2 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-devel-2.48.2-150600.12.40.2 * typelib-1_0-WebKit-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-devel-2.48.2-150600.12.40.2 * typelib-1_0-WebKit-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 ## References: *https://www.suse.com/security/cve/CVE-2023-42875.html * https://www.suse.com/security/cve/CVE-2023-42970.html * https://www.suse.com/security/cve/CVE-2024-23226.html * https://www.suse.com/security/cve/CVE-2025-24223.html * https://www.suse.com/security/cve/CVE-2025-31204.html * https://www.suse.com/security/cve/CVE-2025-31205.html * https://www.suse.com/security/cve/CVE-2025-31206.html * https://www.suse.com/security/cve/CVE-2025-31215.html * https://www.suse.com/security/cve/CVE-2025-31257.html * https://bugzilla.suse.com/show_bug.cgi?id=1222905 * https://bugzilla.suse.com/show_bug.cgi?id=1241158 * https://bugzilla.suse.com/show_bug.cgi?id=1241160 * https://bugzilla.suse.com/show_bug.cgi?id=1243282 * https://bugzilla.suse.com/show_bug.cgi?id=1243286 * https://bugzilla.suse.com/show_bug.cgi?id=1243288 * https://bugzilla.suse.com/show_bug.cgi?id=1243289 * https://bugzilla.suse.com/show_bug.cgi?id=1243424 * https://bugzilla.suse.com/show_bug.cgi?id=1243596 . This enhancement tackles several vital concerns in gtk3-webkit for openSUSE, improving both robustness and safety.. openSUSE Security, webkit2gtk3 Update, Memory Handling Fix. . Severity: Important. LinuxSecurity.com Team
It was discovered that Yelp, the help browser for the GNOME desktop, allowed help files to execute arbitrary scripts. Opening a malformed help file could have resulted in data exfiltration. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5927-1
Get the latest Linux and open source security news straight to your inbox.