Описание
Security update for webkit2gtk3
This update for webkit2gtk3 fixes the following issues:
- CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638).
- CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638).
- CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638).
- CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638).
- CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638).
- CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638).
- CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638).
- CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638).
- CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638).
- CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638).
- CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638).
- CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638).
Changes for webkit2gtk3:
- Update to version 2.52.5:
- Fire scrollend event for instant programmatic scrolls.
- Increase network idle connection timeout to 115 seconds.
- Add User-Agent quirk for HBO Max.
- Fix the build with system malloc.
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
SUSE Linux Enterprise Module for Development Tools 15 SP7
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
Ссылки
- Link for SUSE-SU-2026:3338-1
- E-Mail link for SUSE-SU-2026:3338-1
- SUSE Security Ratings
- SUSE Bug 1271638
- SUSE CVE CVE-2024-4367 page
- SUSE CVE CVE-2026-39872 page
- SUSE CVE CVE-2026-43663 page
- SUSE CVE CVE-2026-43676 page
- SUSE CVE CVE-2026-43699 page
- SUSE CVE CVE-2026-43701 page
- SUSE CVE CVE-2026-43705 page
- SUSE CVE CVE-2026-43707 page
- SUSE CVE CVE-2026-43712 page
- SUSE CVE CVE-2026-43713 page
- SUSE CVE CVE-2026-43715 page
- SUSE CVE CVE-2026-43716 page
- SUSE CVE CVE-2026-43720 page
- SUSE CVE CVE-2026-43721 page
- SUSE CVE CVE-2026-43725 page
- SUSE CVE CVE-2026-43726 page
Описание
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Затронутые продукты
Ссылки
- CVE-2024-4367
- SUSE Bug 1224056
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-39872
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43663
- SUSE Bug 1271638
Описание
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43676
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43699
- SUSE Bug 1271638
Описание
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
Затронутые продукты
Ссылки
- CVE-2026-43701
- SUSE Bug 1271638
Описание
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
Затронутые продукты
Ссылки
- CVE-2026-43705
- SUSE Bug 1271638
Описание
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43707
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43712
- SUSE Bug 1271638
Описание
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website may leak sensitive data.
Затронутые продукты
Ссылки
- CVE-2026-43713
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
Затронутые продукты
Ссылки
- CVE-2026-43715
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43716
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43720
- SUSE Bug 1271638
Описание
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.
Затронутые продукты
Ссылки
- CVE-2026-43721
- SUSE Bug 1271638
Описание
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
Затронутые продукты
Ссылки
- CVE-2026-43725
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43726
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43727
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
Затронутые продукты
Ссылки
- CVE-2026-43731
- SUSE Bug 1271638
Описание
A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
Затронутые продукты
Ссылки
- CVE-2026-43732
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43734
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, Safari 26.6, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.5.2, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may result in the disclosure of process memory.
Затронутые продукты
Ссылки
- CVE-2026-43740
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43742
- SUSE Bug 1271638
Описание
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43745
- SUSE Bug 1271638