gpp_maybe
Security update for webkit2gtk3
SUSE-SLE-Module-Development-Tools-15-SP7-2026-3338
This update for webkit2gtk3 fixes the following issues: - CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). - CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). - CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). - CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). - CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). - CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: - Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc.
-
Release DateJul 28 2026
-
ReferencesBugzilla: 1271638
CVEs: CVE-2026-43663, CVE-2026-43707, CVE-2026-43740, CVE-2026-43732, CVE-2026-43720, CVE-2026-39872, CVE-2026-43699, CVE-2026-43712, CVE-2026-43715, CVE-2026-43705, CVE-2026-43713, CVE-2026-43742, CVE-2026-43701, CVE-2026-43721, CVE-2024-4367, CVE-2026-43716, CVE-2026-43745, CVE-2026-43725, CVE-2026-43734, CVE-2026-43676, CVE-2026-43727, CVE-2026-43726, CVE-2026-43731 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Development Tools Module 15.7 ppc64le
-
Packagestypelib-1_0-JavaScriptCore-6_0
Introspection bindings for the GTK+ port of the JavaScript Core Enginetypelib-1_0-WebKit-6_02.52.5-150600.12.71.1 lock rpm
Introspection bindings for webkit2gtk4typelib-1_0-WebKitWebProcessExtension-6_02.52.5-150600.12.71.1 lock rpm
Introspection bindings for webkit2gtk4webkit2gtk42.52.5-150600.12.71.1 lock rpm
Library for rendering web content, GTK+ Portwebkit2gtk4-devel2.52.5-150600.12.71.1 lock src
Development files for webkit2gtk42.52.5-150600.12.71.1 lock rpm
Development Tools Module 15.7 s390x
-
Packagestypelib-1_0-JavaScriptCore-6_0
Introspection bindings for the GTK+ port of the JavaScript Core Enginetypelib-1_0-WebKit-6_02.52.5-150600.12.71.1 lock rpm
Introspection bindings for webkit2gtk4typelib-1_0-WebKitWebProcessExtension-6_02.52.5-150600.12.71.1 lock rpm
Introspection bindings for webkit2gtk4webkit2gtk42.52.5-150600.12.71.1 lock rpm
Library for rendering web content, GTK+ Portwebkit2gtk4-devel2.52.5-150600.12.71.1 lock src
Development files for webkit2gtk42.52.5-150600.12.71.1 lock rpm
Development Tools Module 15.7 aarch64
-
Packagestypelib-1_0-JavaScriptCore-6_0
Introspection bindings for the GTK+ port of the JavaScript Core Enginetypelib-1_0-WebKit-6_02.52.5-150600.12.71.1 lock rpm
Introspection bindings for webkit2gtk4typelib-1_0-WebKitWebProcessExtension-6_02.52.5-150600.12.71.1 lock rpm
Introspection bindings for webkit2gtk4webkit2gtk42.52.5-150600.12.71.1 lock rpm
Library for rendering web content, GTK+ Portwebkit2gtk4-devel2.52.5-150600.12.71.1 lock src
Development files for webkit2gtk42.52.5-150600.12.71.1 lock rpm
Development Tools Module 15.7 x86_64
-
Packagestypelib-1_0-JavaScriptCore-6_0
Introspection bindings for the GTK+ port of the JavaScript Core Enginetypelib-1_0-WebKit-6_02.52.5-150600.12.71.1 lock rpm
Introspection bindings for webkit2gtk4typelib-1_0-WebKitWebProcessExtension-6_02.52.5-150600.12.71.1 lock rpm
Introspection bindings for webkit2gtk4webkit2gtk42.52.5-150600.12.71.1 lock rpm
Library for rendering web content, GTK+ Portwebkit2gtk4-devel2.52.5-150600.12.71.1 lock src
Development files for webkit2gtk42.52.5-150600.12.71.1 lock rpm