Security update for webkit2gtk3
This update for webkit2gtk3 fixes the following issues: Update to version 2.46.5 (bsc#1234851): Security fixes: - CVE-2024-54479: Processing maliciously crafted web content may lead to an unexpected process crash - CVE-2024-54502: Processing maliciously crafted web content may lead to an unexpected process crash - CVE-2024-54505: Processing maliciously crafted web content may lead to memory corruption - CVE-2024-54508: Processing maliciously crafted web content may lead to an unexpected process crash - CVE-2024-54534: Processing maliciously crafted web content may lead to memory corruption Other fixes: - Fix the build with GBM and release logs disabled. - Fix several crashes and rendering issues. - Improve memory consumption and performance of Canvas getImageData. - Fix preserve-3D intersection rendering. - Fix video dimensions since GStreamer 1.24.9. - Fix the HTTP-based remote Web Inspector not loading in Chromium. - Fix content filters not working on about:blank iframes. - Fix several crashes and rendering issues.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for webkit2gtk3 fixes the following issues: Update to version 2.46.5 (bsc#1234851): Security fixes: - CVE-2024-54479: Processing maliciously crafted web content may lead to an unexpected process crash - CVE-2024-54502: Processing maliciously crafted web content may lead to an unexpected process crash - CVE-2024-54505: Processing maliciously crafted web content may lead to memory corruption - CVE-2024-54508: Processing maliciously crafted web content may lead to an unexpected process crash - CVE-2024-54534: Processing maliciously crafted web content may lead to memory corruption Other fixes: - Fix the build with GBM and release logs disabled. - Fix several crashes and rendering issues. - Improve memory consumption and performance of Canvas getImageData. - Fix preserve-3D intersection rendering. - Fix video dimensions since GStreamer 1.24.9. - Fix the HTTP-based remote Web Inspector not loading in Chromium. - Fix content filters not working on about:blank iframes. - Fix several crashes and rendering issues.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1234851
- https://www.suse.com/security/cve/CVE-2024-40866
- https://www.suse.com/security/cve/CVE-2024-44185
- https://www.suse.com/security/cve/CVE-2024-44187
- https://www.suse.com/security/cve/CVE-2024-44308
- https://www.suse.com/security/cve/CVE-2024-44309
- https://www.suse.com/security/cve/CVE-2024-54479
- https://www.suse.com/security/cve/CVE-2024-54502
- https://www.suse.com/security/cve/CVE-2024-54505
- https://www.suse.com/security/cve/CVE-2024-54508
- https://www.suse.com/security/cve/CVE-2024-54534
- https://www.suse.com/support/update/announcement/2025/suse-su-20250043-1/