{"id":"SUSE-SU-2026:2623-1","summary":"Security update for webkit2gtk3","details":"This update for webkit2gtk3 fixes the following issues\n\nUpdate to version 2.52.4:\n\n- CVE-2026-28847: processing maliciously crafted web content may lead to an unexpected process crash or arbitrary code\n  execution due to a heap buffer overflow (bsc#1267506).\n- CVE-2026-28883: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after-\n  free issue (bsc#1267507).\n- CVE-2026-28901: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1267508).\n- CVE-2026-28902: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1267509).\n- CVE-2026-28903: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1267510).\n- CVE-2026-28904: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1267511).\n- CVE-2026-28905: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1267512).\n- CVE-2026-28907: processing maliciously crafted web content may prevent Content Security Policy from being enforced due\n  to improper input validation (bsc#1267513).\n- CVE-2026-28942: processing maliciously crafted web content may lead to an unexpected crash due to use-after-free\n  (bsc#1267514).\n- CVE-2026-28946: processing maliciously crafted web content may lead to an unexpected crash due to a use-after-free\n  (bsc#1267515).\n- CVE-2026-28947: rocessing maliciously crafted web content may lead to an unexpected crash due to a use-after-free\n  (bsc#1267516).\n- CVE-2026-28953: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1267517).\n- CVE-2026-28955: processing maliciously crafted web content may lead to an unexpected process crash due to improper\n  memory handling (bsc#1267518).\n- CVE-2026-28958: an app may be able to access sensitive user data due to improper data protection (bsc#1267519).\n- CVE-2026-43658: processing maliciously crafted web content may lead to an unexpected crash due to improper memory\n  handling (bsc#1267520).\n- CVE-2026-43660: processing maliciously crafted web content may prevent Content Security Policy from being enforced due\n  to issues with logic (bsc#1267521).\n\nChanges:\n\n + Add support for half-width fonts.\n + Improve content filter compilation by avoiding file copies.\n + Improve handling of out of disk space conditions when the\n NetworkProcess tried to write data in caches.\n + Improve how the CMake build system checks whether libatomic is\n required.\n + Fix painting scrollbars when their width changes.\n + Fix playback of certain YouTube videos with low frame rates.\n + Fix webkit://gpu not working in systems where neither\n libGL.so.1 nor libOpenGL.so.0 are available.\n + Fix the build with librice 0.4 or newer when the GStreamer\n WebRTC backend is enabled at build configuration time.\n + Fix the build with USE_GSTREAMER_WEBRTC=OFF.\n + Fix the build with USE_GBM=OFF.\n + Fix several crashes and rendering issues.\n + Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901,\n CVE-2026-28902, CVE-2026-28903,, CVE-2026-28904,\n CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946,\n CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958,\n CVE-2026-43658, CVe-2026-43660.\n + Add support for the 'scrollbar-color' CSS property.\n + Fix some emoji glyphs being rendered as missing glyph boxes.\n + Fix JavaScriptCore crashes on architectures other than x86_64.\n + Fix the build on s390x.\n + Improve handling of real-time threads.\n + Fix scrollbar rendering glitches visible in some GPU\n configurations.\n + Fix V4L2 hardware accelerated media codecs now working due to\n overly restrictive sandbox device access rules.\n + Fix leak of bitmap images in\n webkit_favicon_database_get_favicon_finish().\n + Fix the build with USE_GTK4=OFF.\n","modified":"2026-06-25T06:15:06.971817007Z","published":"2026-06-24T12:45:43Z","related":["CVE-2026-28847","CVE-2026-28883","CVE-2026-28901","CVE-2026-28902","CVE-2026-28903","CVE-2026-28904","CVE-2026-28905","CVE-2026-28907","CVE-2026-28942","CVE-2026-28946","CVE-2026-28947","CVE-2026-28953","CVE-2026-28955","CVE-2026-28958","CVE-2026-43658","CVE-2026-43660"],"upstream":["CVE-2026-28847","CVE-2026-28883","CVE-2026-28901","CVE-2026-28902","CVE-2026-28903","CVE-2026-28904","CVE-2026-28905","CVE-2026-28907","CVE-2026-28942","CVE-2026-28946","CVE-2026-28947","CVE-2026-28953","CVE-2026-28955","CVE-2026-28958","CVE-2026-43658","CVE-2026-43660"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262623-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267507"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267508"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267509"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267510"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267511"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267512"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267513"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267515"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267516"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267518"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267519"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267520"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267521"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28847"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28883"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28901"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28902"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28903"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28904"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28905"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28907"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28946"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43658"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43660"}],"affected":[{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.52.4-4.60.2"}]}],"ecosystem_specific":{"binaries":[{"libwebkit2gtk-4_0-37":"2.52.4-4.60.2","libwebkit2gtk3-lang":"2.52.4-4.60.2","typelib-1_0-JavaScriptCore-4_0":"2.52.4-4.60.2","typelib-1_0-WebKit2-4_0":"2.52.4-4.60.2","typelib-1_0-WebKit2WebExtension-4_0":"2.52.4-4.60.2","webkit2gtk-4_0-injected-bundles":"2.52.4-4.60.2","webkit2gtk3-devel":"2.52.4-4.60.2","libjavascriptcoregtk-4_0-18":"2.52.4-4.60.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2623-1.json"}},{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.52.4-4.60.2"}]}],"ecosystem_specific":{"binaries":[{"libwebkit2gtk-4_0-37":"2.52.4-4.60.2","libwebkit2gtk3-lang":"2.52.4-4.60.2","typelib-1_0-JavaScriptCore-4_0":"2.52.4-4.60.2","typelib-1_0-WebKit2-4_0":"2.52.4-4.60.2","typelib-1_0-WebKit2WebExtension-4_0":"2.52.4-4.60.2","webkit2gtk-4_0-injected-bundles":"2.52.4-4.60.2","webkit2gtk3-devel":"2.52.4-4.60.2","libjavascriptcoregtk-4_0-18":"2.52.4-4.60.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2623-1.json"}}],"schema_version":"1.7.5"}