Описание
Security update for webkit2gtk3
This update for webkit2gtk3 fixes the following issue:
Security fixes:
- CVE-2024-4367,CVE-2026-39872,CVE-2026-43663,CVE-2026-43676,CVE-2026-43699,CVE-2026-43701, CVE-2026-43705,CVE-2026-43707,CVE-2026-43712,CVE-2026-43713,CVE-2026-43715,CVE-2026-43716, CVE-2026-43720,CVE-2026-43721,CVE-2026-43725,CVE-2026-43726,CVE-2026-43727,CVE-2026-43731, CVE-2026-43732,CVE-2026-43734,CVE-2026-43740,CVE-2026-43742,CVE-2026-43745: WebKitGTK and WPE WebKit Security Advisory WSA-2026-0004 (bsc#1271638).
Other fixes:
- Update to version 2.52.5 (bsc#1271638):
- Fire scrollend event for instant programmatic scrolls.
- Increase network idle connection timeout to 115 seconds.
- Add User-Agent quirk for HBO Max.
- Fix the build with system malloc.
- Fix several crashes and rendering issues.
Список пакетов
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Ссылки
- Link for SUSE-SU-2026:3555-1
- E-Mail link for SUSE-SU-2026:3555-1
- SUSE Security Ratings
- SUSE Bug 1271638
- SUSE CVE CVE-2024-4367 page
- SUSE CVE CVE-2026-39872 page
- SUSE CVE CVE-2026-43663 page
- SUSE CVE CVE-2026-43676 page
- SUSE CVE CVE-2026-43699 page
- SUSE CVE CVE-2026-43701 page
- SUSE CVE CVE-2026-43705 page
- SUSE CVE CVE-2026-43707 page
- SUSE CVE CVE-2026-43712 page
- SUSE CVE CVE-2026-43713 page
- SUSE CVE CVE-2026-43715 page
- SUSE CVE CVE-2026-43716 page
- SUSE CVE CVE-2026-43720 page
- SUSE CVE CVE-2026-43721 page
- SUSE CVE CVE-2026-43725 page
- SUSE CVE CVE-2026-43726 page
Описание
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Затронутые продукты
Ссылки
- CVE-2024-4367
- SUSE Bug 1224056
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-39872
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43663
- SUSE Bug 1271638
Описание
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43676
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43699
- SUSE Bug 1271638
Описание
The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
Затронутые продукты
Ссылки
- CVE-2026-43701
- SUSE Bug 1271638
Описание
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
Затронутые продукты
Ссылки
- CVE-2026-43705
- SUSE Bug 1271638
Описание
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43707
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43712
- SUSE Bug 1271638
Описание
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website may leak sensitive data.
Затронутые продукты
Ссылки
- CVE-2026-43713
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
Затронутые продукты
Ссылки
- CVE-2026-43715
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43716
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43720
- SUSE Bug 1271638
Описание
This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.
Затронутые продукты
Ссылки
- CVE-2026-43721
- SUSE Bug 1271638
Описание
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.
Затронутые продукты
Ссылки
- CVE-2026-43725
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43726
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43727
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.
Затронутые продукты
Ссылки
- CVE-2026-43731
- SUSE Bug 1271638
Описание
A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.
Затронутые продукты
Ссылки
- CVE-2026-43732
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43734
- SUSE Bug 1271638
Описание
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may result in the disclosure of process memory.
Затронутые продукты
Ссылки
- CVE-2026-43740
- SUSE Bug 1271638
Описание
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Затронутые продукты
Ссылки
- CVE-2026-43742
- SUSE Bug 1271638
Описание
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Затронутые продукты
Ссылки
- CVE-2026-43745
- SUSE Bug 1271638