Security update for webkit2gtk3
| Announcement ID: | SUSE-SU-2025:4528-1 |
|---|---|
| Release Date: | 2025-12-26T14:52:38Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves seven vulnerabilities can now be installed.
Description:
This update for webkit2gtk3 fixes the following issues:
Update to version 2.50.4.
Security issues fixed:
- CVE-2025-14174: processing maliciously crafted web content may lead to memory corruption due to improper validation (bsc#1255497).
- CVE-2025-43501: processing maliciously crafted web content may lead to an unexpected process crash due to a buffer overflow issue (bsc#1255194).
- CVE-2025-43529: processing maliciously crafted web content may lead to arbitrary code execution due to a use-after-free issue (bsc#1255198).
- CVE-2025-43531: processing maliciously crafted web content may lead to an unexpected process crash due to a race condition (bsc#1255183).
- CVE-2025-43535: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1255195).
- CVE-2025-43536: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after-free issue (bsc#1255200).
- CVE-2025-43541: processing maliciously crafted web content may lead to an unexpected process crash due to type confusion (bsc#1255191).
Other updates and bugfixes:
- Version 2.50.4:
- Correctly handle the program name passed to the sleep disabler.
- Ensure GStreamer is initialized before using the Quirks.
- Fix several crashes and rendering issues.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server 12 SP5 LTSS
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-4528=1 -
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-4528=1
Package List:
-
SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64)
- webkit2gtk3-debugsource-2.50.4-4.51.1
- libjavascriptcoregtk-4_0-18-2.50.4-4.51.1
- libwebkit2gtk-4_0-37-2.50.4-4.51.1
- libjavascriptcoregtk-4_0-18-debuginfo-2.50.4-4.51.1
- typelib-1_0-WebKit2WebExtension-4_0-2.50.4-4.51.1
- typelib-1_0-JavaScriptCore-4_0-2.50.4-4.51.1
- typelib-1_0-WebKit2-4_0-2.50.4-4.51.1
- webkit2gtk3-devel-2.50.4-4.51.1
- webkit2gtk-4_0-injected-bundles-2.50.4-4.51.1
- libwebkit2gtk-4_0-37-debuginfo-2.50.4-4.51.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS (noarch)
- libwebkit2gtk3-lang-2.50.4-4.51.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64)
- webkit2gtk-4_0-injected-bundles-debuginfo-2.50.4-4.51.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64)
- webkit2gtk3-debugsource-2.50.4-4.51.1
- libjavascriptcoregtk-4_0-18-2.50.4-4.51.1
- libwebkit2gtk-4_0-37-2.50.4-4.51.1
- libjavascriptcoregtk-4_0-18-debuginfo-2.50.4-4.51.1
- typelib-1_0-WebKit2WebExtension-4_0-2.50.4-4.51.1
- typelib-1_0-JavaScriptCore-4_0-2.50.4-4.51.1
- typelib-1_0-WebKit2-4_0-2.50.4-4.51.1
- webkit2gtk3-devel-2.50.4-4.51.1
- webkit2gtk-4_0-injected-bundles-2.50.4-4.51.1
- webkit2gtk-4_0-injected-bundles-debuginfo-2.50.4-4.51.1
- libwebkit2gtk-4_0-37-debuginfo-2.50.4-4.51.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch)
- libwebkit2gtk3-lang-2.50.4-4.51.1
References:
- https://www.suse.com/security/cve/CVE-2025-14174.html
- https://www.suse.com/security/cve/CVE-2025-43501.html
- https://www.suse.com/security/cve/CVE-2025-43529.html
- https://www.suse.com/security/cve/CVE-2025-43531.html
- https://www.suse.com/security/cve/CVE-2025-43535.html
- https://www.suse.com/security/cve/CVE-2025-43536.html
- https://www.suse.com/security/cve/CVE-2025-43541.html
- https://bugzilla.suse.com/show_bug.cgi?id=1255183
- https://bugzilla.suse.com/show_bug.cgi?id=1255191
- https://bugzilla.suse.com/show_bug.cgi?id=1255194
- https://bugzilla.suse.com/show_bug.cgi?id=1255195
- https://bugzilla.suse.com/show_bug.cgi?id=1255198
- https://bugzilla.suse.com/show_bug.cgi?id=1255200
- https://bugzilla.suse.com/show_bug.cgi?id=1255497