Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
100

openSUSE Webkit2gtk3 Important Security Update 2026-2378-1

An update that solves 16 vulnerabilities can now be installed.. # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2026:2378-1 Release Date: 2026-06-11T16:10:30Z Rating: important References: * bsc#1267506 * bsc#1267507 * bsc#1267508 * bsc#1267509 * bsc#1267510 * bsc#1267511 * bsc#1267512 * bsc#1267513 * bsc#1267514 * bsc#1267515 * bsc#1267516 * bsc#1267517 * bsc#1267518 * bsc#1267519 * bsc#1267520 * bsc#1267521 Cross-References: * CVE-2026-28847 * CVE-2026-28883 * CVE-2026-28901 * CVE-2026-28902 * CVE-2026-28903 * CVE-2026-28904 * CVE-2026-28905 * CVE-2026-28907 * CVE-2026-28942 * CVE-2026-28946 * CVE-2026-28947 * CVE-2026-28953 * CVE-2026-28955 * CVE-2026-28958 * CVE-2026-43658 * CVE-2026-43660 CVSS scores: * CVE-2026-28847 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28847 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28847 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28883 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28883 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28883 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28901 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28901 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28901 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-28902 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28902 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28902 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28903 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28903 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28903( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28904 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28904 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28904 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28905 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28905 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28905 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28907 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28907 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-28907 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-28942 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28942 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28942 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28946 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28946 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28947 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28947 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28953 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28953 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28953 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-28955 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28955 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-28955 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28958 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-28958 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-28958 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-43658 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43658 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43658 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43660 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43660 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-43660 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 16 vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues Update to version 2.52.4: * CVE-2026-28847: processing maliciously crafted web content may lead to an unexpected process crash or arbitrary code execution due to a heap buffer overflow (bsc#1267506). * CVE-2026-28883: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after- free issue (bsc#1267507). * CVE-2026-28901: processing maliciously crafted web content may lead to an unexpected process crashdue to improper memory handling (bsc#1267508). * CVE-2026-28902: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267509). * CVE-2026-28903: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267510). * CVE-2026-28904: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267511). * CVE-2026-28905: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267512). * CVE-2026-28907: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to improper input validation (bsc#1267513). * CVE-2026-28942: processing maliciously crafted web content may lead to an unexpected crash due to use-after-free (bsc#1267514). * CVE-2026-28946: processing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267515). * CVE-2026-28947: rocessing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267516). * CVE-2026-28953: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267517). * CVE-2026-28955: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267518). * CVE-2026-28958: an app may be able to access sensitive user data due to improper data protection (bsc#1267519). * CVE-2026-43658: processing maliciously crafted web content may lead to an unexpected crash due to improper memory handling (bsc#1267520). * CVE-2026-43660: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to issues with logic (bsc#1267521). Changes: * Add support for half-width fonts. *Improve content filter compilation by avoiding file copies. * Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. * Improve how the CMake build system checks whether libatomic is required. * Fix painting scrollbars when their width changes. * Fix playback of certain YouTube videos with low frame rates. * Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available. * Fix the build with librice 0.4 or newer when the GStreamer WebRTC backend is enabled at build configuration time. * Fix the build with USE_GSTREAMER_WEBRTC=OFF. * Fix the build with USE_GBM=OFF. * Fix several crashes and rendering issues. * Add support for the "scrollbar-color" CSS property. * Fix some emoji glyphs being rendered as missing glyph boxes. * Fix JavaScriptCore crashes on architectures other than x86_64. * Fix the build on s390x. * Changes in version 2.52.2: * Improve handling of real-time threads. * Fix scrollbar rendering glitches visible in some GPU configurations. * Fix V4L2 hardware accelerated media codecs now working due to overly restrictive sandbox device access rules. * Fix leak of bitmap images in webkit_favicon_database_get_favicon_finish(). * Fix the build with USE_GTK4=OFF. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2378=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2378=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2378=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2378=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2378=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2378=1 ## Package List: * openSUSE Leap 15.4 (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * webkit-jsc-4-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-minibrowser-2.52.4-150400.4.143.1 * webkit-jsc-4.1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * webkit-jsc-6.0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit-6_0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit-jsc-6.0-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-devel-2.52.4-150400.4.143.1 * webkit-jsc-4.1-2.52.4-150400.4.143.1 * webkit-jsc-4-2.52.4-150400.4.143.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * webkit2gtk4-minibrowser-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-minibrowser-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * webkit2gtk4-minibrowser-debuginfo-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * webkit2gtk3-minibrowser-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-6_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * openSUSE Leap 15.4 (x86_64) * libjavascriptcoregtk-4_0-18-32bit-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-32bit-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-32bit-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-32bit-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.4-150400.4.143.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libjavascriptcoregtk-4_1-0-64bit-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-64bit-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-64bit-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-64bit-2.52.4-150400.4.143.1 * SUSE Linux EnterpriseHigh Performance Computing ESPOS 15 SP4 (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 *WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le s390x x86_64) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 s390x) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 *webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * WebKitGTK-4.1-lang-2.52.4-150400.4.143.1 * WebKitGTK-4.0-lang-2.52.4-150400.4.143.1 * WebKitGTK-6.0-lang-2.52.4-150400.4.143.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le) * libwebkit2gtk-4_0-37-2.52.4-150400.4.143.1 * webkitgtk-6_0-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk4-debugsource-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.4-150400.4.143.1 *libjavascriptcoregtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.4-150400.4.143.1 * libjavascriptcoregtk-6_0-1-2.52.4-150400.4.143.1 * webkit2gtk-4_1-injected-bundles-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_1-2.52.4-150400.4.143.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_1-0-2.52.4-150400.4.143.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_0-2.52.4-150400.4.143.1 * webkit2gtk3-devel-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-debugsource-2.52.4-150400.4.143.1 * typelib-1_0-WebKit2-4_0-2.52.4-150400.4.143.1 * libwebkitgtk-6_0-4-2.52.4-150400.4.143.1 * typelib-1_0-JavaScriptCore-4_1-2.52.4-150400.4.143.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.4-150400.4.143.1 * webkit2gtk3-debugsource-2.52.4-150400.4.143.1 * webkit2gtk3-soup2-devel-2.52.4-150400.4.143.1 * libwebkit2gtk-4_1-0-2.52.4-150400.4.143.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28847.html * https://www.suse.com/security/cve/CVE-2026-28883.html * https://www.suse.com/security/cve/CVE-2026-28901.html * https://www.suse.com/security/cve/CVE-2026-28902.html * https://www.suse.com/security/cve/CVE-2026-28903.html * https://www.suse.com/security/cve/CVE-2026-28904.html * https://www.suse.com/security/cve/CVE-2026-28905.html * https://www.suse.com/security/cve/CVE-2026-28907.html * https://www.suse.com/security/cve/CVE-2026-28942.html * https://www.suse.com/security/cve/CVE-2026-28946.html * https://www.suse.com/security/cve/CVE-2026-28947.html * https://www.suse.com/security/cve/CVE-2026-28953.html *https://www.suse.com/security/cve/CVE-2026-28955.html * https://www.suse.com/security/cve/CVE-2026-28958.html * https://www.suse.com/security/cve/CVE-2026-43658.html * https://www.suse.com/security/cve/CVE-2026-43660.html * https://bugzilla.suse.com/show_bug.cgi?id=1267506 * https://bugzilla.suse.com/show_bug.cgi?id=1267507 * https://bugzilla.suse.com/show_bug.cgi?id=1267508 * https://bugzilla.suse.com/show_bug.cgi?id=1267509 * https://bugzilla.suse.com/show_bug.cgi?id=1267510 * https://bugzilla.suse.com/show_bug.cgi?id=1267511 * https://bugzilla.suse.com/show_bug.cgi?id=1267512 * https://bugzilla.suse.com/show_bug.cgi?id=1267513 * https://bugzilla.suse.com/show_bug.cgi?id=1267514 * https://bugzilla.suse.com/show_bug.cgi?id=1267515 * https://bugzilla.suse.com/show_bug.cgi?id=1267516 * https://bugzilla.suse.com/show_bug.cgi?id=1267517 * https://bugzilla.suse.com/show_bug.cgi?id=1267518 * https://bugzilla.suse.com/show_bug.cgi?id=1267519 * https://bugzilla.suse.com/show_bug.cgi?id=1267520 * https://bugzilla.suse.com/show_bug.cgi?id=1267521 . Security update for webkit2gtk3 resolves 16 vulnerabilities in openSUSE, ensuring safer web content handling. Install now!. openSUSE update, webkit2gtk3 security, important update, memory handling issues, open source security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 11, 2026 Important SuSE
89

Fedora 44 qt6-qtwebview Issue Resolution 2026-70776c2dc4

Qt 6.10.3 bugfix update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-70776c2dc3 2026-04-25 01:21:36.172096+00:00 -------------------------------------------------------------------------------- Name : qt6-qtwebview Product : Fedora 44 Version : 6.10.3 Release : 1.fc44 URL : http://www.qt.io Summary : Qt6 - WebView component Description : Qt WebView provides a way to display web content in a QML application without necessarily including a full web browser stack by using native APIs where it makes sense. -------------------------------------------------------------------------------- Update Information: Qt 6.10.3 bugfix update. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 2 2026 Jan Grulich - 6.10.3-1 - 6.10.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-70776c2dc3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it:https://forge.fedoraproject.org/infra/tickets/issues/new . Qt 6.10.3 bugfix update for Fedora 44 enhances web content display in applications with new improvements.. Qt 6.10.3, Fedora 44, qtwebview, bugfix update, web content. . LinuxSecurity.com Team

Calendar%202 Apr 25, 2026 Fedora
203

Important Vulnerabilities in Webkit2 for Mageia MGASA-2025-0325 and CVEs

MGASA-2025-0325 - Updated webkit2 packages fix security vulnerabilities. MGASA-2025-0325 - Updated webkit2 packages fix security vulnerabilities Publication date: 09 Dec 2025 URL: https://advisories.mageia.org/MGASA-2025-0325.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-13947, CVE-2025-43421, CVE-2025-43458, CVE-2025-66287 Description: A website may be able to exfiltrate sensitive system information. Description: The issue was addressed through improved state checks - CVE-2025-13947. Processing maliciously crafted web content may lead to an unexpected process crash. Description: Multiple issues were addressed by disabling array allocation sinking - CVE-2025-43421. Processing maliciously crafted web content may lead to an unexpected process crash. Description: This issue was addressed through improved state management - CVE-2025-43458. Processing maliciously crafted web content may lead to an unexpected process crash. Description: The issue was addressed with improved memory handling - CVE-2025-66287. References: - https://bugs.mageia.org/show_bug.cgi?id=34802 - https://webkitgtk.org/security/WSA-2025-0009.html - https://webkitgtk.org/2025/12/04/webkitgtk2.50.3-released.html - https://www.cve.org/CVERecord?id=CVE-2025-13947 - https://www.cve.org/CVERecord?id=CVE-2025-43421 - https://www.cve.org/CVERecord?id=CVE-2025-43458 - https://www.cve.org/CVERecord?id=CVE-2025-66287 SRPMS: - 9/core/webkit2-2.50.3-1.mga9 . Updated webkit2 packages on Mageia address issues like unexpected crashes and sensitive information exposure.. Webkit2 Security Update, Mageia Advisory, Process Crash Vulnerability, Information Disclosure Mageia, Security Patch Webkit2. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 09, 2025 Important Mageia
89

Fedora 42: qt5-qtwebview Important Bugfix 2025-976ccd79ae

Qt 5.15.18 bugfix release. Qt5 WebEngine update to 5.15.19.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-976ccd79ae 2025-11-06 02:22:59.541317+00:00 -------------------------------------------------------------------------------- Name : qt5-qtwebview Product : Fedora 42 Version : 5.15.18 Release : 1.fc42 URL : http://www.qt.io Summary : Qt5 - WebView component Description : Qt WebView provides a way to display web content in a QML application without necessarily including a full web browser stack by using native APIs where it makes sense. -------------------------------------------------------------------------------- Update Information: Qt 5.15.18 bugfix release. Qt5 WebEngine update to 5.15.19. -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 4 2025 Jan Grulich - 5.15.18-1 - 5.15.18 * Fri Jul 25 2025 Fedora Release Engineering - 5.15.17-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-976ccd79ae' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Qt 5.15.18 bugfix release for Fedora addresses important updates in WebView and WebEngine components.. Fedora qt5-qtwebview update release bugfix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 06, 2025 Important Fedora
89

Fedora 41: Critical Denial of Service Advisory for webkitgtk 2.48.5

Update to 2.48.5. Changes since 2.48.3: Improve emoji font selection. Improve playback of multimedia streams from blob URLs. Fix crash when using a WebKitWebView widget in an offscreen window. Fix several crashes and rendering issues.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-9b8165a4b3 2025-08-22 02:11:10.530849+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 41 Version : 2.48.5 Release : 1.fc41 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Update to 2.48.5. Changes since 2.48.3: Improve emoji font selection. Improve playback of multimedia streams from blob URLs. Fix crash when using a WebKitWebView widget in an offscreen window. Fix several crashes and rendering issues. CVE-2025-31273, CVE-2025-31278, CVE-2025-43211, CVE-2025-43212, CVE-2025-43216, CVE-2025-43227, CVE-2025-43240, CVE-2025-43265, CVE-2025-6558 -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 5 2025 Michael Catanzaro - 2.48.5-1 - Update to 2.48.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2386383 - CVE-2025-43265 webkitgtk: Processing maliciously crafted web content may disclose internal states of the app [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386383 [ 2 ] Bug #2386384 - CVE-2025-43227 webkitgtk: Processing maliciously crafted web content may disclose sensitive user information [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386384 [ 3 ] Bug #2386387 - CVE-2025-43216 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386387 [ 4 ] Bug #2386390 - CVE-2025-43212 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386390 [ 5 ] Bug #2386397 - CVE-2025-43211 webkitgtk: Processing web content may lead to a denial-of-service [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386397 [ 6 ] Bug #2386406 - CVE-2025-31278 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386406 [ 7 ] Bug #2386409 - CVE-2025-31273 webkitgtk: Processing maliciously crafted web content may lead to memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386409 [ 8 ] Bug #2386415 - CVE-2025-43240 webkitgtk: A download\u2019s origin may be incorrectly associated [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2386415 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9b8165a4b3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 41 upgrade to webkitgtk 2.48.5 resolves significant vulnerabilities and improves video streaming performance.. Fedora 41, WebKitGTK 2.48.5, security advisory, multimedia streaming, denial-of-service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 22, 2025 Critical Fedora
100

openSUSE Leap 15.6: 2025:01746-1 important: webkit2gtk3 patch

* bsc#1222905 * bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 . # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2025:01746-1 Release Date: 2025-05-29T12:38:02Z Rating: important References: * bsc#1222905 * bsc#1241158 * bsc#1241160 * bsc#1243282 * bsc#1243286 * bsc#1243288 * bsc#1243289 * bsc#1243424 * bsc#1243596 Cross-References: * CVE-2023-42875 * CVE-2023-42970 * CVE-2024-23226 * CVE-2025-24223 * CVE-2025-31204 * CVE-2025-31205 * CVE-2025-31206 * CVE-2025-31215 * CVE-2025-31257 CVSS scores: * CVE-2023-42875 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2023-42875 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2023-42875 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2023-42970 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-42970 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-42970 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-23226 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-23226 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-23226 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24223 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-24223 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24223 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-31204 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-31204 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-31205 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-31205 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-31206 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-31206 ( NVD ): 4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-31215 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-31215 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-31257 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-31257 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-31257 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP6 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: Update to version 2.48.2. Security issues fixed: * CVE-2025-31205: lack of checks may lead to cross-origin data exfiltration through a malicious website (bsc#1243282). * CVE-2025-31204: improper memory handling when processing certain web content may lead to memory corruption (bsc#1243286). * CVE-2025-31206: type confusion issue when processing certain web content may lead to an unexpected crash (bsc#1243288). * CVE-2025-31215: lack of checks when processing certain web content may lead to an unexpected crash (bsc#1243289). * CVE-2025-31257: improper memory handling when processing certain web content may lead to an unexpected crash (bsc#1243596). * CVE-2025-24223: improper memory handling when processing certain web content may lead to memory corruption(bsc#1243424). Other changes and issues fixed: * Enable CSS overscroll behavior by default. * Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. * Fix rendering when device scale factor change comes before the web view geometry update. * Fix network process crash on exit. * Fix the build with ENABLE_RESOURCE_USAGE=OFF. * Fix several crashes and rendering issues. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1746=1 openSUSE-SLE-15.6-2025-1746=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1746=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-1746=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1746=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1746=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-1746=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2025-1746=1 ## Package List: * openSUSE Leap 15.6 (noarch) * WebKitGTK-4.1-lang-2.48.2-150600.12.40.2 * WebKitGTK-4.0-lang-2.48.2-150600.12.40.2 * WebKitGTK-6.0-lang-2.48.2-150600.12.40.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * webkit2gtk-4_1-injected-bundles-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-minibrowser-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_1-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_0-2.48.2-150600.12.40.2 *typelib-1_0-WebKit2-4_0-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-2.48.2-150600.12.40.2 * webkit-jsc-6.0-2.48.2-150600.12.40.2 * webkit2gtk3-devel-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-minibrowser-debuginfo-2.48.2-150600.12.40.2 * webkit-jsc-4-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * webkit-jsc-6.0-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_1-2.48.2-150600.12.40.2 * webkit2gtk4-minibrowser-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * webkit-jsc-4-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-debugsource-2.48.2-150600.12.40.2 * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-minibrowser-2.48.2-150600.12.40.2 * webkit2gtk3-minibrowser-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-6_0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-minibrowser-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_1-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-2.48.2-150600.12.40.2 * webkit-jsc-4.1-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-devel-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-2.48.2-150600.12.40.2 * webkit-jsc-4.1-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk4-devel-2.48.2-150600.12.40.2 *webkit2gtk3-soup2-debugsource-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 * openSUSE Leap 15.6 (x86_64) * libjavascriptcoregtk-4_1-0-32bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-32bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-32bit-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-32bit-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.48.2-150600.12.40.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libjavascriptcoregtk-4_1-0-64bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-64bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-64bit-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-64bit-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.48.2-150600.12.40.2 * Basesystem Module 15-SP6 (noarch) * WebKitGTK-4.0-lang-2.48.2-150600.12.40.2 * WebKitGTK-6.0-lang-2.48.2-150600.12.40.2 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-4_0-18-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-devel-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_0-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_0-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-2.48.2-150600.12.40.2 *libjavascriptcoregtk-4_0-18-debuginfo-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-debugsource-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_0-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 * Basesystem Module 15-SP7 (noarch) * WebKitGTK-4.0-lang-2.48.2-150600.12.40.2 * WebKitGTK-6.0-lang-2.48.2-150600.12.40.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-4_0-18-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-devel-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_0-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_0-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-2.48.2-150600.12.40.2 * libwebkit2gtk-4_0-37-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.48.2-150600.12.40.2 * webkitgtk-6_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_0-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk3-soup2-debugsource-2.48.2-150600.12.40.2 * libwebkitgtk-6_0-4-2.48.2-150600.12.40.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_0-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 * Desktop Applications Module 15-SP6 (noarch) * WebKitGTK-4.1-lang-2.48.2-150600.12.40.2 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * webkit2gtk-4_1-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.2-150600.12.40.2 *libwebkit2gtk-4_1-0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_1-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-debugsource-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_1-2.48.2-150600.12.40.2 * webkit2gtk3-devel-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_1-2.48.2-150600.12.40.2 * Desktop Applications Module 15-SP7 (noarch) * WebKitGTK-4.1-lang-2.48.2-150600.12.40.2 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * webkit2gtk-4_1-injected-bundles-2.48.2-150600.12.40.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * libjavascriptcoregtk-4_1-0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-4_1-2.48.2-150600.12.40.2 * libwebkit2gtk-4_1-0-debuginfo-2.48.2-150600.12.40.2 * webkit2gtk3-debugsource-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2WebExtension-4_1-2.48.2-150600.12.40.2 * webkit2gtk3-devel-2.48.2-150600.12.40.2 * typelib-1_0-WebKit2-4_1-2.48.2-150600.12.40.2 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-devel-2.48.2-150600.12.40.2 * typelib-1_0-WebKit-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.2-150600.12.40.2 * typelib-1_0-JavaScriptCore-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-devel-2.48.2-150600.12.40.2 * typelib-1_0-WebKit-6_0-2.48.2-150600.12.40.2 * webkit2gtk4-debugsource-2.48.2-150600.12.40.2 ## References: *https://www.suse.com/security/cve/CVE-2023-42875.html * https://www.suse.com/security/cve/CVE-2023-42970.html * https://www.suse.com/security/cve/CVE-2024-23226.html * https://www.suse.com/security/cve/CVE-2025-24223.html * https://www.suse.com/security/cve/CVE-2025-31204.html * https://www.suse.com/security/cve/CVE-2025-31205.html * https://www.suse.com/security/cve/CVE-2025-31206.html * https://www.suse.com/security/cve/CVE-2025-31215.html * https://www.suse.com/security/cve/CVE-2025-31257.html * https://bugzilla.suse.com/show_bug.cgi?id=1222905 * https://bugzilla.suse.com/show_bug.cgi?id=1241158 * https://bugzilla.suse.com/show_bug.cgi?id=1241160 * https://bugzilla.suse.com/show_bug.cgi?id=1243282 * https://bugzilla.suse.com/show_bug.cgi?id=1243286 * https://bugzilla.suse.com/show_bug.cgi?id=1243288 * https://bugzilla.suse.com/show_bug.cgi?id=1243289 * https://bugzilla.suse.com/show_bug.cgi?id=1243424 * https://bugzilla.suse.com/show_bug.cgi?id=1243596 . This enhancement tackles several vital concerns in gtk3-webkit for openSUSE, improving both robustness and safety.. openSUSE Security, webkit2gtk3 Update, Memory Handling Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 29, 2025 Important SuSE
202

openSUSE: 2025:1149-1 moderate: webkit2gtk3 information disclosure fix

An update that solves three vulnerabilities can now be installed.. # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2025:1149-1 Release Date: 2025-04-07T07:12:51Z Rating: moderate References: * bsc#1239863 * bsc#1239864 * bsc#1239950 Cross-References: * CVE-2024-44192 * CVE-2024-54467 * CVE-2025-24201 CVSS scores: * CVE-2024-44192 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-44192 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-44192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-44192 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-54467 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-54467 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-54467 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-54467 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-24201 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24201 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24201 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP6 * Desktop Applications Module 15-SP6 * Development Tools Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: * CVE-2024-44192: Fixed unexpected process crash due to processing maliciously crafted web content (bsc#1239863) * CVE-2024-54467: Fixed information disclosure via data cross-origin exfiltration due to a cookie management issue (bsc#1239864) Other fixes: * Update to version2.48.0: * Move tiles rendering to worker threads when rendering with the GPU. * Fix preserve-3D intersection rendering. * Added new function for creating Promise objects to JavaScripotCore GLib API. * The MediaRecorder backend gained WebM support (requires at least GStreamer 1.24.9) and audio bitrate configuration support. * Fix invalid DPI-aware font size conversion. * Bring back support for OpenType-SVG fonts using Skia SVG module. * Add metadata (title and creation/modification date) to the PDF document generated for printing. * Propagate the font’s computed locale to HarfBuzz. * The GPU process build is now enabled for WebGL, but the web process is still used by default. The runtime flag UseGPUProcessForWebGL can be used to use the GPU process for WebGL. * Security fixes: CVE-2024-44192, CVE-2024-54467, CVE-2025-24201. * Disable speech synthesis. It has been disabled until now, and we don't have flite or spiel in SLE. * Add gcc13-PIE to BuildRequires (bsc#1239950). * Backport upstream patch to stop using IOChannel in NetworkCache: hopefully fixes crashes in the network process. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1149=1 SUSE-2025-1149=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1149=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1149=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-1149=1 ## Package List: * openSUSE Leap 15.6 (noarch) * WebKitGTK-6.0-lang-2.48.0-150600.12.33.1 * WebKitGTK-4.1-lang-2.48.0-150600.12.33.1 * WebKitGTK-4.0-lang-2.48.0-150600.12.33.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libjavascriptcoregtk-6_0-1-debuginfo-2.48.0-150600.12.33.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.0-150600.12.33.1 * libwebkit2gtk-4_1-0-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk3-soup2-devel-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_0-18-2.48.0-150600.12.33.1 * webkit2gtk3-soup2-debugsource-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.48.0-150600.12.33.1 * typelib-1_0-WebKit2WebExtension-4_1-2.48.0-150600.12.33.1 * typelib-1_0-JavaScriptCore-4_0-2.48.0-150600.12.33.1 * typelib-1_0-WebKit2WebExtension-4_0-2.48.0-150600.12.33.1 * webkit-jsc-4.1-2.48.0-150600.12.33.1 * webkit2gtk3-soup2-minibrowser-2.48.0-150600.12.33.1 * webkit-jsc-4-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk3-minibrowser-2.48.0-150600.12.33.1 * typelib-1_0-WebKit2-4_0-2.48.0-150600.12.33.1 * typelib-1_0-WebKit-6_0-2.48.0-150600.12.33.1 * webkit2gtk3-debugsource-2.48.0-150600.12.33.1 * webkit2gtk3-minibrowser-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk-4_0-injected-bundles-2.48.0-150600.12.33.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.0-150600.12.33.1 * typelib-1_0-JavaScriptCore-6_0-2.48.0-150600.12.33.1 * webkit2gtk4-debugsource-2.48.0-150600.12.33.1 * webkit-jsc-6.0-debuginfo-2.48.0-150600.12.33.1 * webkit-jsc-6.0-2.48.0-150600.12.33.1 * libwebkit2gtk-4_0-37-debuginfo-2.48.0-150600.12.33.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.0-150600.12.33.1 * webkit2gtk4-minibrowser-debuginfo-2.48.0-150600.12.33.1 * webkit-jsc-4.1-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk4-devel-2.48.0-150600.12.33.1 * typelib-1_0-JavaScriptCore-4_1-2.48.0-150600.12.33.1 * webkit2gtk-4_1-injected-bundles-2.48.0-150600.12.33.1 * libwebkitgtk-6_0-4-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.0-150600.12.33.1 *libjavascriptcoregtk-6_0-1-2.48.0-150600.12.33.1 * libwebkit2gtk-4_1-0-2.48.0-150600.12.33.1 * libwebkitgtk-6_0-4-2.48.0-150600.12.33.1 * webkit2gtk3-devel-2.48.0-150600.12.33.1 * libwebkit2gtk-4_0-37-2.48.0-150600.12.33.1 * webkit2gtk4-minibrowser-2.48.0-150600.12.33.1 * webkitgtk-6_0-injected-bundles-2.48.0-150600.12.33.1 * webkit-jsc-4-2.48.0-150600.12.33.1 * typelib-1_0-WebKit2-4_1-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_1-0-2.48.0-150600.12.33.1 * openSUSE Leap 15.6 (x86_64) * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_1-0-32bit-2.48.0-150600.12.33.1 * libwebkit2gtk-4_1-0-32bit-2.48.0-150600.12.33.1 * libwebkit2gtk-4_0-37-32bit-2.48.0-150600.12.33.1 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.48.0-150600.12.33.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_0-18-32bit-2.48.0-150600.12.33.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libwebkit2gtk-4_1-0-64bit-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.48.0-150600.12.33.1 * libwebkit2gtk-4_0-37-64bit-2.48.0-150600.12.33.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.48.0-150600.12.33.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_1-0-64bit-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_0-18-64bit-2.48.0-150600.12.33.1 * Basesystem Module 15-SP6 (noarch) * WebKitGTK-6.0-lang-2.48.0-150600.12.33.1 * WebKitGTK-4.0-lang-2.48.0-150600.12.33.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libwebkitgtk-6_0-4-debuginfo-2.48.0-150600.12.33.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk4-debugsource-2.48.0-150600.12.33.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.0-150600.12.33.1 *libwebkit2gtk-4_0-37-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk3-soup2-devel-2.48.0-150600.12.33.1 * typelib-1_0-JavaScriptCore-4_0-2.48.0-150600.12.33.1 * libwebkitgtk-6_0-4-2.48.0-150600.12.33.1 * libjavascriptcoregtk-6_0-1-2.48.0-150600.12.33.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.0-150600.12.33.1 * libwebkit2gtk-4_0-37-2.48.0-150600.12.33.1 * typelib-1_0-WebKit2WebExtension-4_0-2.48.0-150600.12.33.1 * webkitgtk-6_0-injected-bundles-2.48.0-150600.12.33.1 * typelib-1_0-WebKit2-4_0-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_0-18-2.48.0-150600.12.33.1 * webkit2gtk3-soup2-debugsource-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.48.0-150600.12.33.1 * webkit2gtk-4_0-injected-bundles-2.48.0-150600.12.33.1 * Desktop Applications Module 15-SP6 (noarch) * WebKitGTK-4.1-lang-2.48.0-150600.12.33.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.0-150600.12.33.1 * typelib-1_0-WebKit2WebExtension-4_1-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.0-150600.12.33.1 * libwebkit2gtk-4_1-0-2.48.0-150600.12.33.1 * webkit2gtk3-devel-2.48.0-150600.12.33.1 * typelib-1_0-WebKit2-4_1-2.48.0-150600.12.33.1 * typelib-1_0-JavaScriptCore-4_1-2.48.0-150600.12.33.1 * libwebkit2gtk-4_1-0-debuginfo-2.48.0-150600.12.33.1 * libjavascriptcoregtk-4_1-0-2.48.0-150600.12.33.1 * webkit2gtk3-debugsource-2.48.0-150600.12.33.1 * webkit2gtk-4_1-injected-bundles-2.48.0-150600.12.33.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * webkit2gtk4-debugsource-2.48.0-150600.12.33.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.0-150600.12.33.1 * webkit2gtk4-devel-2.48.0-150600.12.33.1 * typelib-1_0-WebKit-6_0-2.48.0-150600.12.33.1 * typelib-1_0-JavaScriptCore-6_0-2.48.0-150600.12.33.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44192.html *https://www.suse.com/security/cve/CVE-2024-54467.html * https://www.suse.com/security/cve/CVE-2025-24201.html * https://bugzilla.suse.com/show_bug.cgi?id=1239863 * https://bugzilla.suse.com/show_bug.cgi?id=1239864 * https://bugzilla.suse.com/show_bug.cgi?id=1239950 . This patch resolves essential concerns in webkit2gtk3 for openSUSE, providing security improvements and resolving bugs.. openSUSE security, webkit2gtk3 update, security patch, process crash fix. . LinuxSecurity.com Team

Calendar%202 Apr 07, 2025 OpenSUSE
100

SUSE: 2025:1033-1 moderate: webkit2gtk3 Security Advisory Updates

* bsc#1239863 * bsc#1239864 * bsc#1239950 Cross-References: . # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2025:1033-1 Release Date: 2025-03-26T15:44:39Z Rating: moderate References: * bsc#1239863 * bsc#1239864 * bsc#1239950 Cross-References: * CVE-2024-44192 * CVE-2024-54467 * CVE-2025-24201 CVSS scores: * CVE-2024-44192 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-44192 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-44192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-44192 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-54467 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-54467 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-54467 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-54467 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-24201 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24201 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24201 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves three vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: * CVE-2024-44192: Fixed unexpected process crash due to processing maliciously crafted web content (bsc#1239863) * CVE-2024-54467: Fixed data exilfration cross-origin due to a cookie management issue via a malicious website (bsc#1239864) Other fixes: \- Update to version 2.48.0 \+ Move tiles rendering to worker threads when rendering with the GPU. \+ Fix preserve-3D intersection rendering. \+ Added new function for creating Promise objects to JavaScripotCore GLib API. \+ The MediaRecorder backend gained WebM support (requires at least GStreamer 1.24.9) and audiobitrate configuration support. \+ Fix invalid DPI-aware font size conversion. \+ Bring back support for OpenType-SVG fonts using Skia SVG module. \+ Add metadata (title and creation/modification date) to the PDF document generated for printing. \+ Propagate the font’s computed locale to HarfBuzz. \+ The GPU process build is now enabled for WebGL, but the web process is still used by default. The runtime flag UseGPUProcessForWebGL can be used to use the GPU process for WebGL. \- Add gcc13-PIE to BuildRequires (bsc#1239950). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1033=1 ## Package List: * openSUSE Leap 15.4 (noarch) * WebKitGTK-6.0-lang-2.48.0-150400.4.112.1 * WebKitGTK-4.0-lang-2.48.0-150400.4.112.1 * WebKitGTK-4.1-lang-2.48.0-150400.4.112.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * typelib-1_0-WebKit2-4_1-2.48.0-150400.4.112.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.48.0-150400.4.112.1 * typelib-1_0-WebKit-6_0-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_1-0-2.48.0-150400.4.112.1 * typelib-1_0-JavaScriptCore-6_0-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.48.0-150400.4.112.1 * webkit2gtk4-minibrowser-2.48.0-150400.4.112.1 * libjavascriptcoregtk-6_0-1-2.48.0-150400.4.112.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.48.0-150400.4.112.1 * libwebkit2gtk-4_0-37-debuginfo-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.48.0-150400.4.112.1 * webkit2gtk3-soup2-debugsource-2.48.0-150400.4.112.1 * webkit2gtk3-soup2-devel-2.48.0-150400.4.112.1 * typelib-1_0-JavaScriptCore-4_1-2.48.0-150400.4.112.1 * webkit-jsc-6.0-2.48.0-150400.4.112.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.48.0-150400.4.112.1 * webkit2gtk3-minibrowser-2.48.0-150400.4.112.1 *webkit-jsc-4-debuginfo-2.48.0-150400.4.112.1 * webkit-jsc-4-2.48.0-150400.4.112.1 * webkit-jsc-4.1-debuginfo-2.48.0-150400.4.112.1 * webkit-jsc-6.0-debuginfo-2.48.0-150400.4.112.1 * typelib-1_0-JavaScriptCore-4_0-2.48.0-150400.4.112.1 * webkit2gtk-4_0-injected-bundles-2.48.0-150400.4.112.1 * webkit2gtk3-soup2-minibrowser-2.48.0-150400.4.112.1 * libwebkitgtk-6_0-4-debuginfo-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_0-18-2.48.0-150400.4.112.1 * webkit2gtk4-debugsource-2.48.0-150400.4.112.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.48.0-150400.4.112.1 * webkit2gtk4-minibrowser-debuginfo-2.48.0-150400.4.112.1 * typelib-1_0-WebKit2WebExtension-4_1-2.48.0-150400.4.112.1 * webkit2gtk3-debugsource-2.48.0-150400.4.112.1 * webkit-jsc-4.1-2.48.0-150400.4.112.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.48.0-150400.4.112.1 * webkit2gtk3-devel-2.48.0-150400.4.112.1 * webkitgtk-6_0-injected-bundles-2.48.0-150400.4.112.1 * libwebkit2gtk-4_1-0-debuginfo-2.48.0-150400.4.112.1 * webkit2gtk-4_1-injected-bundles-2.48.0-150400.4.112.1 * webkit2gtk3-minibrowser-debuginfo-2.48.0-150400.4.112.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.48.0-150400.4.112.1 * typelib-1_0-WebKit2WebExtension-4_0-2.48.0-150400.4.112.1 * webkit2gtk4-devel-2.48.0-150400.4.112.1 * libwebkit2gtk-4_1-0-2.48.0-150400.4.112.1 * libwebkit2gtk-4_0-37-2.48.0-150400.4.112.1 * typelib-1_0-WebKit2-4_0-2.48.0-150400.4.112.1 * libwebkitgtk-6_0-4-2.48.0-150400.4.112.1 * openSUSE Leap 15.4 (x86_64) * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.48.0-150400.4.112.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.48.0-150400.4.112.1 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.48.0-150400.4.112.1 * libwebkit2gtk-4_1-0-32bit-2.48.0-150400.4.112.1 * libwebkit2gtk-4_0-37-32bit-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_0-18-32bit-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_1-0-32bit-2.48.0-150400.4.112.1 *libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.48.0-150400.4.112.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libwebkit2gtk-4_1-0-64bit-2.48.0-150400.4.112.1 * libwebkit2gtk-4_0-37-64bit-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.48.0-150400.4.112.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_1-0-64bit-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.48.0-150400.4.112.1 * libjavascriptcoregtk-4_0-18-64bit-2.48.0-150400.4.112.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.48.0-150400.4.112.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44192.html * https://www.suse.com/security/cve/CVE-2024-54467.html * https://www.suse.com/security/cve/CVE-2025-24201.html * https://bugzilla.suse.com/show_bug.cgi?id=1239863 * https://bugzilla.suse.com/show_bug.cgi?id=1239864 * https://bugzilla.suse.com/show_bug.cgi?id=1239950 . Important updates for webkit2gtk3 address critical issues including process crashes and data leaks for openSUSE.. bsc#1239863, bsc#1239864, bsc#1239950, cross-references, security, update, webkit2gtk3, announ. . LinuxSecurity.com Team

Calendar%202 Mar 26, 2025 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200