Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 16 vulnerabilities can now be installed.. # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2026:2623-1 Release Date: 2026-06-24T12:45:47Z Rating: important References: * bsc#1267506 * bsc#1267507 * bsc#1267508 * bsc#1267509 * bsc#1267510 * bsc#1267511 * bsc#1267512 * bsc#1267513 * bsc#1267514 * bsc#1267515 * bsc#1267516 * bsc#1267517 * bsc#1267518 * bsc#1267519 * bsc#1267520 * bsc#1267521 Cross-References: * CVE-2026-28847 * CVE-2026-28883 * CVE-2026-28901 * CVE-2026-28902 * CVE-2026-28903 * CVE-2026-28904 * CVE-2026-28905 * CVE-2026-28907 * CVE-2026-28942 * CVE-2026-28946 * CVE-2026-28947 * CVE-2026-28953 * CVE-2026-28955 * CVE-2026-28958 * CVE-2026-43658 * CVE-2026-43660 CVSS scores: * CVE-2026-28847 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28847 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28847 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28883 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28883 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28883 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28901 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28901 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28901 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-28902 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28902 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28902 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28903 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28903 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28903( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28904 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28904 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28904 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28905 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28905 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28905 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28907 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28907 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-28907 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-28942 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28942 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28942 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28946 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28946 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28947 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28947 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28953 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28953 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28953 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28955 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28955 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28955 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28958 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-28958 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-28958 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43658 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43658 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43658 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43660 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43660 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-43660 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 16 vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues Update to version 2.52.4: * CVE-2026-28847: processing maliciously crafted web content may lead to an unexpected process crash or arbitrary code execution due to a heap buffer overflow (bsc#1267506). * CVE-2026-28883: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after- free issue (bsc#1267507). * CVE-2026-28901: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267508). * CVE-2026-28902: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267509). * CVE-2026-28903: processingmaliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267510). * CVE-2026-28904: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267511). * CVE-2026-28905: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267512). * CVE-2026-28907: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to improper input validation (bsc#1267513). * CVE-2026-28942: processing maliciously crafted web content may lead to an unexpected crash due to use-after-free (bsc#1267514). * CVE-2026-28946: processing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267515). * CVE-2026-28947: rocessing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267516). * CVE-2026-28953: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267517). * CVE-2026-28955: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267518). * CVE-2026-28958: an app may be able to access sensitive user data due to improper data protection (bsc#1267519). * CVE-2026-43658: processing maliciously crafted web content may lead to an unexpected crash due to improper memory handling (bsc#1267520). * CVE-2026-43660: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to issues with logic (bsc#1267521). Changes: * Add support for half-width fonts. * Improve content filter compilation by avoiding file copies. * Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. * Improve how the CMake build system checks whether libatomicis required. * Fix painting scrollbars when their width changes. * Fix playback of certain YouTube videos with low frame rates. * Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available. * Fix the build with librice 0.4 or newer when the GStreamer WebRTC backend is enabled at build configuration time. * Fix the build with USE_GSTREAMER_WEBRTC=OFF. * Fix the build with USE_GBM=OFF. * Fix several crashes and rendering issues. * Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903,, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658, CVe-2026-43660. * Add support for the "scrollbar-color" CSS property. * Fix some emoji glyphs being rendered as missing glyph boxes. * Fix JavaScriptCore crashes on architectures other than x86_64. * Fix the build on s390x. * Improve handling of real-time threads. * Fix scrollbar rendering glitches visible in some GPU configurations. * Fix V4L2 hardware accelerated media codecs now working due to overly restrictive sandbox device access rules. * Fix leak of bitmap images in webkit_favicon_database_get_favicon_finish(). * Fix the build with USE_GTK4=OFF. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2623=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2623=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-4_0-18-2.52.4-4.60.2 * webkit2gtk3-debugsource-2.52.4-4.60.2 * libwebkit2gtk-4_0-37-2.52.4-4.60.2 * typelib-1_0-JavaScriptCore-4_0-2.52.4-4.60.2 * typelib-1_0-WebKit2-4_0-2.52.4-4.60.2 * webkit2gtk-4_0-injected-bundles-2.52.4-4.60.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-4.60.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-4.60.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-4.60.2 * webkit2gtk3-devel-2.52.4-4.60.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * libwebkit2gtk3-lang-2.52.4-4.60.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-4.60.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libjavascriptcoregtk-4_0-18-2.52.4-4.60.2 * webkit2gtk3-debugsource-2.52.4-4.60.2 * libwebkit2gtk-4_0-37-2.52.4-4.60.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-4.60.2 * typelib-1_0-JavaScriptCore-4_0-2.52.4-4.60.2 * typelib-1_0-WebKit2-4_0-2.52.4-4.60.2 * webkit2gtk-4_0-injected-bundles-2.52.4-4.60.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-4.60.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-4.60.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-4.60.2 * webkit2gtk3-devel-2.52.4-4.60.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libwebkit2gtk3-lang-2.52.4-4.60.2 ## References: * https://www.suse.com/security/cve/CVE-2026-28847.html * https://www.suse.com/security/cve/CVE-2026-28883.html * https://www.suse.com/security/cve/CVE-2026-28901.html * https://www.suse.com/security/cve/CVE-2026-28902.html * https://www.suse.com/security/cve/CVE-2026-28903.html * https://www.suse.com/security/cve/CVE-2026-28904.html * https://www.suse.com/security/cve/CVE-2026-28905.html * https://www.suse.com/security/cve/CVE-2026-28907.html * https://www.suse.com/security/cve/CVE-2026-28942.html * https://www.suse.com/security/cve/CVE-2026-28946.html * https://www.suse.com/security/cve/CVE-2026-28947.html * https://www.suse.com/security/cve/CVE-2026-28953.html *https://www.suse.com/security/cve/CVE-2026-28955.html * https://www.suse.com/security/cve/CVE-2026-28958.html * https://www.suse.com/security/cve/CVE-2026-43658.html * https://www.suse.com/security/cve/CVE-2026-43660.html * https://bugzilla.suse.com/show_bug.cgi?id=1267506 * https://bugzilla.suse.com/show_bug.cgi?id=1267507 * https://bugzilla.suse.com/show_bug.cgi?id=1267508 * https://bugzilla.suse.com/show_bug.cgi?id=1267509 * https://bugzilla.suse.com/show_bug.cgi?id=1267510 * https://bugzilla.suse.com/show_bug.cgi?id=1267511 * https://bugzilla.suse.com/show_bug.cgi?id=1267512 * https://bugzilla.suse.com/show_bug.cgi?id=1267513 * https://bugzilla.suse.com/show_bug.cgi?id=1267514 * https://bugzilla.suse.com/show_bug.cgi?id=1267515 * https://bugzilla.suse.com/show_bug.cgi?id=1267516 * https://bugzilla.suse.com/show_bug.cgi?id=1267517 * https://bugzilla.suse.com/show_bug.cgi?id=1267518 * https://bugzilla.suse.com/show_bug.cgi?id=1267519 * https://bugzilla.suse.com/show_bug.cgi?id=1267520 * https://bugzilla.suse.com/show_bug.cgi?id=1267521 . This update addresses significant vulnerabilities in webkit2gtk3, improving security against crafted web content attacks. . SUSE webkit2gtk3 update, important updates SUSE, software vulnerabilities fixed. . Severity: Important. LinuxSecurity.com Team
An update that solves 16 vulnerabilities can now be installed.. # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2026:22212-1 Release Date: 2026-06-20T09:26:54Z Rating: important References: * bsc#1267506 * bsc#1267507 * bsc#1267508 * bsc#1267509 * bsc#1267510 * bsc#1267511 * bsc#1267512 * bsc#1267513 * bsc#1267514 * bsc#1267515 * bsc#1267516 * bsc#1267517 * bsc#1267518 * bsc#1267519 * bsc#1267520 * bsc#1267521 Cross-References: * CVE-2026-28847 * CVE-2026-28883 * CVE-2026-28901 * CVE-2026-28902 * CVE-2026-28903 * CVE-2026-28904 * CVE-2026-28905 * CVE-2026-28907 * CVE-2026-28942 * CVE-2026-28946 * CVE-2026-28947 * CVE-2026-28953 * CVE-2026-28955 * CVE-2026-28958 * CVE-2026-43658 * CVE-2026-43660 CVSS scores: * CVE-2026-28847 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28847 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28847 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28883 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28883 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28883 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28901 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28901 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28901 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-28902 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28902 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28902 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28903 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28903 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28903( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28904 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28904 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28904 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28905 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28905 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28905 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28907 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28907 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-28907 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-28942 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28942 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28942 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28946 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28946 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28947 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28947 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28953 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28953 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28953 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28955 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28955 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28955 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28958 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-28958 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-28958 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43658 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43658 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43658 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43660 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43660 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-43660 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 16 vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues Update to version 2.52.4: * CVE-2026-28847: processing maliciously crafted web content may lead to an unexpected process crash or arbitrary code execution due to a heap buffer overflow (bsc#1267506). * CVE-2026-28883: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after- free issue (bsc#1267507). * CVE-2026-28901: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267508). * CVE-2026-28902: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267509). * CVE-2026-28903: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267510). * CVE-2026-28904: processing maliciously crafted webcontent may lead to an unexpected process crash due to improper memory handling (bsc#1267511). * CVE-2026-28905: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267512). * CVE-2026-28907: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to improper input validation (bsc#1267513). * CVE-2026-28942: processing maliciously crafted web content may lead to an unexpected crash due to use-after-free (bsc#1267514). * CVE-2026-28946: processing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267515). * CVE-2026-28947: rocessing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267516). * CVE-2026-28953: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267517). * CVE-2026-28955: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267518). * CVE-2026-28958: an app may be able to access sensitive user data due to improper data protection (bsc#1267519). * CVE-2026-43658: processing maliciously crafted web content may lead to an unexpected crash due to improper memory handling (bsc#1267520). * CVE-2026-43660: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to issues with logic (bsc#1267521). Changes for webkit2gtk3: * Add support for half-width fonts. * Improve content filter compilation by avoiding file copies. * Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. * Improve how the CMake build system checks whether libatomic is required. * Fix painting scrollbars when their width changes. * Fix playback of certain YouTube videos with low frame rates. * Fix webkit://gpu notworking in systems where neither libGL.so.1 nor libOpenGL.so.0 are available. * Fix the build with librice 0.4 or newer when the GStreamer WebRTC backend is enabled at build configuration time. * Fix the build with USE_GSTREAMER_WEBRTC=OFF. * Fix the build with USE_GBM=OFF. * Fix several crashes and rendering issues. * Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658, CVe-2026-43660. * Changes in version .52.3; * Add support for the "scrollbar-color" CSS property. * Fix some emoji glyphs being rendered as missing glyph boxes. * Fix JavaScriptCore crashes on architectures other than x86_64. * Fix the build on s390x. * Changes in version 2.52.2: * Improve handling of real-time threads. * Fix scrollbar rendering glitches visible in some GPU configurations. * Fix V4L2 hardware accelerated media codecs now working due to overly restrictive sandbox device access rules. * Fix leak of bitmap images in webkit_favicon_database_get_favicon_finish(). * Fix the build with USE_GTK4=OFF. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-994=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-994=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libjavascriptcoregtk-6_0-1-2.52.4-160000.1.1 * webkit2gtk-4_1-injected-bundles-2.52.4-160000.1.1 * webkit-jsc-4.1-2.52.4-160000.1.1 * typelib-1_0-WebKit-6_0-2.52.4-160000.1.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-160000.1.1 * webkit-jsc-6.0-2.52.4-160000.1.1 *webkitgtk-6_0-injected-bundles-debuginfo-2.52.4-160000.1.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-160000.1.1 * libwebkit2gtk-4_1-0-2.52.4-160000.1.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.4-160000.1.1 * webkit-jsc-4.1-debuginfo-2.52.4-160000.1.1 * libwebkitgtk-6_0-4-2.52.4-160000.1.1 * webkit-jsc-6.0-debuginfo-2.52.4-160000.1.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-160000.1.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-160000.1.1 * webkit2gtk4-minibrowser-2.52.4-160000.1.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-160000.1.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-160000.1.1 * webkit2gtk3-minibrowser-debuginfo-2.52.4-160000.1.1 * webkit2gtk3-minibrowser-2.52.4-160000.1.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-160000.1.1 * typelib-1_0-JavaScriptCore-6_0-2.52.4-160000.1.1 * webkit2gtk4-minibrowser-debuginfo-2.52.4-160000.1.1 * libjavascriptcoregtk-4_1-0-2.52.4-160000.1.1 * webkitgtk-6_0-injected-bundles-2.52.4-160000.1.1 * typelib-1_0-WebKit2-4_1-2.52.4-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * WebKitGTK-6.0-lang-2.52.4-160000.1.1 * WebKitGTK-4.1-lang-2.52.4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-6_0-1-2.52.4-160000.1.1 * webkit2gtk-4_1-injected-bundles-2.52.4-160000.1.1 * webkit-jsc-4.1-2.52.4-160000.1.1 * typelib-1_0-WebKit-6_0-2.52.4-160000.1.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-160000.1.1 * webkit-jsc-6.0-2.52.4-160000.1.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.4-160000.1.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-160000.1.1 * libwebkit2gtk-4_1-0-2.52.4-160000.1.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.4-160000.1.1 * webkit-jsc-4.1-debuginfo-2.52.4-160000.1.1 * libwebkitgtk-6_0-4-2.52.4-160000.1.1 * webkit-jsc-6.0-debuginfo-2.52.4-160000.1.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-160000.1.1 *libwebkit2gtk-4_1-0-debuginfo-2.52.4-160000.1.1 * webkit2gtk4-minibrowser-2.52.4-160000.1.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-160000.1.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-160000.1.1 * webkit2gtk3-minibrowser-debuginfo-2.52.4-160000.1.1 * webkit2gtk3-minibrowser-2.52.4-160000.1.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-160000.1.1 * typelib-1_0-JavaScriptCore-6_0-2.52.4-160000.1.1 * webkit2gtk4-minibrowser-debuginfo-2.52.4-160000.1.1 * libjavascriptcoregtk-4_1-0-2.52.4-160000.1.1 * webkitgtk-6_0-injected-bundles-2.52.4-160000.1.1 * typelib-1_0-WebKit2-4_1-2.52.4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * WebKitGTK-6.0-lang-2.52.4-160000.1.1 * WebKitGTK-4.1-lang-2.52.4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28847.html * https://www.suse.com/security/cve/CVE-2026-28883.html * https://www.suse.com/security/cve/CVE-2026-28901.html * https://www.suse.com/security/cve/CVE-2026-28902.html * https://www.suse.com/security/cve/CVE-2026-28903.html * https://www.suse.com/security/cve/CVE-2026-28904.html * https://www.suse.com/security/cve/CVE-2026-28905.html * https://www.suse.com/security/cve/CVE-2026-28907.html * https://www.suse.com/security/cve/CVE-2026-28942.html * https://www.suse.com/security/cve/CVE-2026-28946.html * https://www.suse.com/security/cve/CVE-2026-28947.html * https://www.suse.com/security/cve/CVE-2026-28953.html * https://www.suse.com/security/cve/CVE-2026-28955.html * https://www.suse.com/security/cve/CVE-2026-28958.html * https://www.suse.com/security/cve/CVE-2026-43658.html * https://www.suse.com/security/cve/CVE-2026-43660.html * https://bugzilla.suse.com/show_bug.cgi?id=1267506 * https://bugzilla.suse.com/show_bug.cgi?id=1267507 * https://bugzilla.suse.com/show_bug.cgi?id=1267508 * https://bugzilla.suse.com/show_bug.cgi?id=1267509 * https://bugzilla.suse.com/show_bug.cgi?id=1267510 * https://bugzilla.suse.com/show_bug.cgi?id=1267511 *https://bugzilla.suse.com/show_bug.cgi?id=1267512 * https://bugzilla.suse.com/show_bug.cgi?id=1267513 * https://bugzilla.suse.com/show_bug.cgi?id=1267514 * https://bugzilla.suse.com/show_bug.cgi?id=1267515 * https://bugzilla.suse.com/show_bug.cgi?id=1267516 * https://bugzilla.suse.com/show_bug.cgi?id=1267517 * https://bugzilla.suse.com/show_bug.cgi?id=1267518 * https://bugzilla.suse.com/show_bug.cgi?id=1267519 * https://bugzilla.suse.com/show_bug.cgi?id=1267520 * https://bugzilla.suse.com/show_bug.cgi?id=1267521 . This important SUSE update resolves 16 vulnerabilities in webkit2gtk3, enhancing security and fixing critical issues.. SUSE webkit2gtk3 vulnerabilities update, SUSE security fix, important SUSE advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves 16 vulnerabilities can now be installed.. # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2026:2378-1 Release Date: 2026-06-11T16:10:30Z Rating: important References: * bsc#1267506 * bsc#1267507 * bsc#1267508 * bsc#1267509 * bsc#1267510 * bsc#1267511 * bsc#1267512 * bsc#1267513 * bsc#1267514 * bsc#1267515 * bsc#1267516 * bsc#1267517 * bsc#1267518 * bsc#1267519 * bsc#1267520 * bsc#1267521 Cross-References: * CVE-2026-28847 * CVE-2026-28883 * CVE-2026-28901 * CVE-2026-28902 * CVE-2026-28903 * CVE-2026-28904 * CVE-2026-28905 * CVE-2026-28907 * CVE-2026-28942 * CVE-2026-28946 * CVE-2026-28947 * CVE-2026-28953 * CVE-2026-28955 * CVE-2026-28958 * CVE-2026-43658 * CVE-2026-43660 CVSS scores: * CVE-2026-28847 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28847 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28847 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28883 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28883 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28883 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28901 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28901 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28901 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-28902 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28902 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28902 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28903 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28903 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28903( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28904 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28904 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28904 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28905 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28905 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28905 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28907 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28907 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-28907 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-28942 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28942 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28942 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28946 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28946 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28947 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28947 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28953 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28953 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28953 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28955 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28955 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28955 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28958 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-28958 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-28958 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43658 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43658 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43658 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43660 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43660 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-43660 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 16 vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues Update to version 2.52.4: * CVE-2026-28847: processing maliciously crafted web content may lead to an unexpected process crash or arbitrary code execution due to a heap buffer overflow (bsc#1267506). * CVE-2026-28883: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after- free issue (bsc#1267507). * CVE-2026-28901: processing maliciously crafted web content may lead to an unexpected process crashdue to improper memory handling (bsc#1267508). * CVE-2026-28902: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267509). * CVE-2026-28903: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267510). * CVE-2026-28904: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267511). * CVE-2026-28905: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267512). * CVE-2026-28907: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to improper input validation (bsc#1267513). * CVE-2026-28942: processing maliciously crafted web content may lead to an unexpected crash due to use-after-free (bsc#1267514). * CVE-2026-28946: processing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267515). * CVE-2026-28947: rocessing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267516). * CVE-2026-28953: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267517). * CVE-2026-28955: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267518). * CVE-2026-28958: an app may be able to access sensitive user data due to improper data protection (bsc#1267519). * CVE-2026-43658: processing maliciously crafted web content may lead to an unexpected crash due to improper memory handling (bsc#1267520). * CVE-2026-43660: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to issues with logic (bsc#1267521). Changes: * Add support for half-width fonts. *Improve content filter compilation by avoiding file copies. * Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. * Improve how the CMake build system checks whether libatomic is required. * Fix painting scrollbars when their width changes. * Fix playback of certain YouTube videos with low frame rates. * Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available. * Fix the build with librice 0.4 or newer when the GStreamer WebRTC backend is enabled at build configuration time. * Fix the build with USE_GSTREAMER_WEBRTC=OFF. * Fix the build with USE_GBM=OFF. * Fix several crashes and rendering issues. * Add support for the "scrollbar-color" CSS property. * Fix some emoji glyphs being rendered as missing glyph boxes. * Fix JavaScriptCore crashes on architectures other than x86_64. * Fix the build on s390x. * Changes in version 2.52.2: * Improve handling of real-time threads. * Fix scrollbar rendering glitches visible in some GPU configurations. * Fix V4L2 hardware accelerated media codecs now working due to overly restrictive sandbox device access rules. * Fix leak of bitmap images in webkit_favicon_database_get_favicon_finish(). * Fix the build with USE_GTK4=OFF. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2378=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2378=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2378=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2378=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2378=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2378=1 ## Package List: * openSUSE Leap 15.4 (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * webkit-jsc-4-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-minibrowser-2.52.4-150400.4.143.1 * webkit-jsc-4.1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * webkit-jsc-6.0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit-6_0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit-jsc-6.0-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-devel-2.52.4-150400.4.143.1 * webkit-jsc-4.1-2.52.4-150400.4.143.1 * webkit-jsc-4-2.52.4-150400.4.143.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * webkit2gtk4-minibrowser-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-minibrowser-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * webkit2gtk4-minibrowser-debuginfo-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * webkit2gtk3-minibrowser-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-6_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * openSUSE Leap 15.4 (x86_64) * libjavascriptcoregtk-4_0-18-32bit-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-32bit-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-32bit-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-32bit-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.4-150400.4.143.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libjavascriptcoregtk-4_1-0-64bit-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-64bit-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-64bit-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-64bit-2.52.4-150400.4.143.1 * SUSE Linux EnterpriseHigh Performance Computing ESPOS 15 SP4 (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 *WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le s390x x86_64) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 s390x) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 *webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 *libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28847.html * https://www.suse.com/security/cve/CVE-2026-28883.html * https://www.suse.com/security/cve/CVE-2026-28901.html * https://www.suse.com/security/cve/CVE-2026-28902.html * https://www.suse.com/security/cve/CVE-2026-28903.html * https://www.suse.com/security/cve/CVE-2026-28904.html * https://www.suse.com/security/cve/CVE-2026-28905.html * https://www.suse.com/security/cve/CVE-2026-28907.html * https://www.suse.com/security/cve/CVE-2026-28942.html * https://www.suse.com/security/cve/CVE-2026-28946.html * https://www.suse.com/security/cve/CVE-2026-28947.html * https://www.suse.com/security/cve/CVE-2026-28953.html *https://www.suse.com/security/cve/CVE-2026-28955.html * https://www.suse.com/security/cve/CVE-2026-28958.html * https://www.suse.com/security/cve/CVE-2026-43658.html * https://www.suse.com/security/cve/CVE-2026-43660.html * https://bugzilla.suse.com/show_bug.cgi?id=1267506 * https://bugzilla.suse.com/show_bug.cgi?id=1267507 * https://bugzilla.suse.com/show_bug.cgi?id=1267508 * https://bugzilla.suse.com/show_bug.cgi?id=1267509 * https://bugzilla.suse.com/show_bug.cgi?id=1267510 * https://bugzilla.suse.com/show_bug.cgi?id=1267511 * https://bugzilla.suse.com/show_bug.cgi?id=1267512 * https://bugzilla.suse.com/show_bug.cgi?id=1267513 * https://bugzilla.suse.com/show_bug.cgi?id=1267514 * https://bugzilla.suse.com/show_bug.cgi?id=1267515 * https://bugzilla.suse.com/show_bug.cgi?id=1267516 * https://bugzilla.suse.com/show_bug.cgi?id=1267517 * https://bugzilla.suse.com/show_bug.cgi?id=1267518 * https://bugzilla.suse.com/show_bug.cgi?id=1267519 * https://bugzilla.suse.com/show_bug.cgi?id=1267520 * https://bugzilla.suse.com/show_bug.cgi?id=1267521 . An important security update for openSUSE addresses 16 vulnerabilities in webkit2gtk3, ensuring safer web content processing.. webkit2gtk3 update, openSUSE vulnerabilities, security advisory openSUSE, openSUSE 2026 update, security patch webkit2gtk3. . Severity: Important. LinuxSecurity.com Team
Update to 2.52.1. Notable changes from 2.50 to 2.52: Make text look like in other browsers by blending in linear color space. Improved rendering performance by using a different tile size depending on whether GPU rendering is enabled or not.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-36594550b0 2026-04-14 01:07:38.489371+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 42 Version : 2.52.1 Release : 1.fc42 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Update to 2.52.1. Notable changes from 2.50 to 2.52: Make text look like in other browsers by blending in linear color space. Improved rendering performance by using a different tile size depending on whether GPU rendering is enabled or not. Improved composition scheduling to avoid blocking waiting for tile painting. Improved performance of accelerated 2D canvas by recording operations for batched replay. Improved async scrolling when main thread is busy by avoiding locks and rendering the scrollbars from the scrolling thread. Enabled dynamic MSAA for accelerated 2D canvas rendering. Improved text rendering performance Videos with BT2100-PQ colorspace are now tone-mapped to SDR, ensuring colours do not appear washed out. Added support for the Audio Output Devices API. Added API to handle WebXR permission requests. Added API to query the immersive session status. Added initial API for web extensions. Additional changes from 2.52.0 to 2.52.1: Reduce the amount of useless MPRIS notifications produced by MediaSesion when the information about media being played is incomplete. Add Sysprof marks for mouse events. Fix MediaSessionicon for iheart.com not being displayed. Fix several crashes and rendering issues. Translation updates: Georgian. -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 28 2026 Michael Catanzaro - 2.52.1-1 - Update to 2.52.1 * Sat Mar 21 2026 Michael Catanzaro - 2.52.0-1 - Update to 2.52.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449069 - CVE-2025-43213 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449069 [ 2 ] Bug #2449073 - CVE-2025-43214 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449073 [ 3 ] Bug #2449086 - CVE-2025-43457 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449086 [ 4 ] Bug #2449089 - CVE-2025-43511 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449089 [ 5 ] Bug #2449092 - CVE-2025-46299 webkitgtk: Processing maliciously crafted web content may disclose internal states of the app [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449092 [ 6 ] Bug #2449095 - CVE-2026-20608 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449095 [ 7 ] Bug #2449098 - CVE-2026-20635 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449098 [ 8 ] Bug #2449102 - CVE-2026-20636 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449102 [ 9 ] Bug #2449105 - CVE-2026-20644 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449105 [ 10 ] Bug #2449108 - CVE-2026-20652 webkitgtk: A remote attacker may be able to cause a denial-of-service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449108 [ 11 ] Bug #2449111 - CVE-2026-20676 webkitgtk: A website may be able to track users through Safari web extensions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449111 [ 12 ] Bug #2450634 - webkitgtk-2.50.5: WebKitWebProcess repeated SIGABRT crashes (heap corruption), upstream fixed in 2.50.6+ https://bugzilla.redhat.com/show_bug.cgi?id=2450634 [ 13 ] Bug #2453064 - CVE-2026-20643 webkitgtk: Processing maliciously crafted web content may bypass Same Origin Policy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453064 [ 14 ] Bug #2453067 - CVE-2026-20664 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453067 [ 15 ] Bug #2453070 - CVE-2026-20665 webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453070 [ 16 ] Bug #2453073 - CVE-2026-20691 webkitgtk: A maliciously crafted webpage may be able to fingerprint the user [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453073 [ 17 ] Bug #2453076 - CVE-2026-28857 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453076 [ 18 ] Bug #2453079 - CVE-2026-28859 webkitgtk: A malicious website may be able to process restricted web content outside the sandbox [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453079 [ 19 ] Bug #2453082 - CVE-2026-28871 webkitgtk: Visiting a maliciously crafted website may lead to a cross-site scripting attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453082 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-36594550b0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43214 shandikri discovered that processing maliciously crafted web content may lead to an unexpected process crash.. Debian LTS Advisory DLA-4528-1
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43392 Tom Van Goethem discovered that a website may exfiltrate image data cross-origin.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6070-1
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-43272 Big Bear discovered that processing maliciously crafted web content may lead to an unexpected process crash.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6042-1
Update to 2.48.5. Changes since 2.48.3: Improve emoji font selection. Improve playback of multimedia streams from blob URLs. Fix crash when using a WebKitWebView widget in an offscreen window. Fix several crashes and rendering issues.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-61ca72f430 2025-08-08 00:53:07.924008+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 42 Version : 2.48.5 Release : 1.fc42 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Update to 2.48.5. Changes since 2.48.3: Improve emoji font selection. Improve playback of multimedia streams from blob URLs. Fix crash when using a WebKitWebView widget in an offscreen window. Fix several crashes and rendering issues. CVE-2025-31273, CVE-2025-31278, CVE-2025-43211, CVE-2025-43212, CVE-2025-43216, CVE-2025-43227, CVE-2025-43240, CVE-2025-43265, CVE-2025-6558 -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 5 2025 Michael Catanzaro - 2.48.5-1 - Update to 2.48.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2386383 - CVE-2025-43265 webkitgtk: Processing maliciously crafted web content may disclose internal states of the app [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386383 [ 2 ] Bug #2386384 - CVE-2025-43227 webkitgtk: Processing maliciously crafted web content may disclose sensitive user information [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386384 [ 3 ] Bug #2386387 - CVE-2025-43216 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386387 [ 4 ] Bug #2386390 - CVE-2025-43212 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386390 [ 5 ] Bug #2386397 - CVE-2025-43211 webkitgtk: Processing web content may lead to a denial-of-service [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386397 [ 6 ] Bug #2386406 - CVE-2025-31278 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386406 [ 7 ] Bug #2386409 - CVE-2025-31273 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386409 [ 8 ] Bug #2386415 - CVE-2025-43240 webkitgtk: A download\u2019s origin may be incorrectly associated [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386415 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-61ca72f430' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . The upgrade to webkitgtk 2.48.5 in Fedora 42 tackles major security vulnerabilities and enhances audio-visual playback capabilities.. Fedora WebKitGTK Update Memory Corruption Denial of Service. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.