Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3338-1

Опубликовано: 28 июл. 2026
Источник: suse-cvrf

Описание

Security update for webkit2gtk3

This update for webkit2gtk3 fixes the following issues:

  • CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638).
  • CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
  • CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
  • CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638).
  • CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638).
  • CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638).
  • CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638).
  • CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638).
  • CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
  • CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638).
  • CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638).
  • CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638).
  • CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638).
  • CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638).
  • CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638).
  • CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638).
  • CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638).
  • CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638).
  • CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638).
  • CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638).
  • CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638).
  • CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638).
  • CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638).

Changes for webkit2gtk3:

  • Update to version 2.52.5:
  • Fire scrollend event for instant programmatic scrolls.
  • Increase network idle connection timeout to 115 seconds.
  • Add User-Agent quirk for HBO Max.
  • Fix the build with system malloc.

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP7
WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
webkit2gtk3-devel-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
webkit2gtk4-devel-2.52.5-150600.12.71.1
SUSE Linux Enterprise Server 15 SP6-LTSS
WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
webkit2gtk3-devel-2.52.5-150600.12.71.1
webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
webkit2gtk4-devel-2.52.5-150600.12.71.1
webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
webkit2gtk3-devel-2.52.5-150600.12.71.1
webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
webkit2gtk4-devel-2.52.5-150600.12.71.1
webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1

Ссылки

Описание

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website may leak sensitive data.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, Safari 26.6, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.5.2, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may result in the disclosure of process memory.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки

Описание

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1

Ссылки
Уязвимость SUSE-SU-2026:3338-1