Security update for webkit2gtk3
This update for webkit2gtk3 fixes the following issues: Update to version 2.52.0: - CVE-2023-43010: processing maliciously crafted web content may lead to memory corruption (bsc#1259950). - CVE-2025-31223: processing maliciously crafted web content may lead to memory corruption (bsc#1259949). - CVE-2025-31277: processing maliciously crafted web content may lead to memory corruption (bsc#1259948). - CVE-2025-43213: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259947). - CVE-2025-43214: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259946). - CVE-2025-43433: processing maliciously crafted web content may lead to memory corruption (bsc#1259945). - CVE-2025-43438: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259944). - CVE-2025-43441: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259943). - CVE-2025-43457: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259942). - CVE-2025-43511: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259941). - CVE-2025-46299: processing maliciously crafted web content may disclose internal states of an app (bsc#1259940). - CVE-2026-20608: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259939). - CVE-2026-20635: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259938). - CVE-2026-20636: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259937). - CVE-2026-20644: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259936). - CVE-2026-20652: a remote attacker may be able to cause a denial-of-service (bsc#1259935). - CVE-2026-20676: a website may be able to track users through web extensions (bsc#1259934). Changelog: + Make scrolling with touch input smoother for small movements. + Fix estimated load progress of downloads when Content-Length value is wrong. + Ensure that 'scrollend' events are correctly emitted after scroll animations. + Fix several crashes and rendering issues.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for webkit2gtk3 fixes the following issues: Update to version 2.52.0: - CVE-2023-43010: processing maliciously crafted web content may lead to memory corruption (bsc#1259950). - CVE-2025-31223: processing maliciously crafted web content may lead to memory corruption (bsc#1259949). - CVE-2025-31277: processing maliciously crafted web content may lead to memory corruption (bsc#1259948). - CVE-2025-43213: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259947). - CVE-2025-43214: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259946). - CVE-2025-43433: processing maliciously crafted web content may lead to memory corruption (bsc#1259945). - CVE-2025-43438: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259944). - CVE-2025-43441: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259943). - CVE-2025-43457: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259942). - CVE-2025-43511: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259941). - CVE-2025-46299: processing maliciously crafted web content may disclose internal states of an app (bsc#1259940). - CVE-2026-20608: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259939). - CVE-2026-20635: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259938). - CVE-2026-20636: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259937). - CVE-2026-20644: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259936). - CVE-2026-20652: a remote attacker may be able to cause a denial-of-service (bsc#1259935). - CVE-2026-20676: a website may be able to track users through web extensions (bsc#1259934). Changelog: + Make scrolling with touch input smoother for small movements. + Fix estimated load progress of downloads when Content-Length value is wrong. + Ensure that 'scrollend' events are correctly emitted after scroll animations. + Fix several crashes and rendering issues.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1259934
- https://bugzilla.suse.com/1259935
- https://bugzilla.suse.com/1259936
- https://bugzilla.suse.com/1259937
- https://bugzilla.suse.com/1259938
- https://bugzilla.suse.com/1259939
- https://bugzilla.suse.com/1259940
- https://bugzilla.suse.com/1259941
- https://bugzilla.suse.com/1259942
- https://bugzilla.suse.com/1259943
- https://bugzilla.suse.com/1259944
- https://bugzilla.suse.com/1259945
- https://bugzilla.suse.com/1259946
- https://bugzilla.suse.com/1259947
- https://bugzilla.suse.com/1259948
- https://bugzilla.suse.com/1259949
- https://bugzilla.suse.com/1259950
- https://www.suse.com/security/cve/CVE-2023-42843
- https://www.suse.com/security/cve/CVE-2023-43010
- https://www.suse.com/security/cve/CVE-2024-54658
- https://www.suse.com/security/cve/CVE-2025-13502
- https://www.suse.com/security/cve/CVE-2025-31223
- https://www.suse.com/security/cve/CVE-2025-31277
- https://www.suse.com/security/cve/CVE-2025-43213
- https://www.suse.com/security/cve/CVE-2025-43214
- https://www.suse.com/security/cve/CVE-2025-43368
- https://www.suse.com/security/cve/CVE-2025-43419
- https://www.suse.com/security/cve/CVE-2025-43433
- https://www.suse.com/security/cve/CVE-2025-43434
- https://www.suse.com/security/cve/CVE-2025-43438
- https://www.suse.com/security/cve/CVE-2025-43440
- https://www.suse.com/security/cve/CVE-2025-43441
- https://www.suse.com/security/cve/CVE-2025-43443
- https://www.suse.com/security/cve/CVE-2025-43457
- https://www.suse.com/security/cve/CVE-2025-43511
- https://www.suse.com/security/cve/CVE-2025-46299
- https://www.suse.com/security/cve/CVE-2026-20608
- https://www.suse.com/security/cve/CVE-2026-20635
- https://www.suse.com/security/cve/CVE-2026-20636
- https://www.suse.com/security/cve/CVE-2026-20644
- https://www.suse.com/security/cve/CVE-2026-20652
- https://www.suse.com/security/cve/CVE-2026-20676
- https://www.suse.com/support/update/announcement/2026/suse-su-20261150-1/