Back Linuxsecurity openSUSE Leap 15.4 webkit2gtk3 Important Memory Issues Vuln 2026-1150
This update for webkit2gtk3 fixes the following issues: Update to version 2.52.0: * CVE-2023-43010: processing maliciously crafted web content may lead to memory corruption (bsc#1259950). * CVE-2025-31223: processing maliciously crafted web content may lead to memory corruption (bsc#1259949). * CVE-2025-31277: processing maliciously crafted web content may lead to memory corruption (bsc#1259948). * CVE-2025-43213: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259947). * CVE-2025-43214: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259946). * CVE-2025-43433: processing maliciously crafted web content may lead to memory corruption (bsc#1259945). * CVE-2025-43438: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259944). * CVE-2025-43441: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259943). *
## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1150=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1150=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1150=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1150=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1150=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1150=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch Read the Full Advisory
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
zypper in -t patch SUSE-2026-1150=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1150=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1150=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1150=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1150=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1150=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
* openSUSE Leap 15.4 (noarch) * WebKitGTK-4.1-lang-2.52.0-150400.4.137.3 * WebKitGTK-4.0-lang-2.52.0-150400.4.137.3 * WebKitGTK-6.0-lang-2.52.0-150400.4.137.3 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * webkitgtk-6_0-injected-bundles-debuginfo-2.52.0-150400.4.137.3 * webkit-jsc-4-debuginfo-2.52.0-150400.4.137.3 * typelib-1_0-JavaScriptCore-4_0-2.52.0-150400.4.137.3 * libjavascriptcoregtk-6_0-1-2.52.0-150400.4.137.3 * webkit-jsc-6.0-2.52.0-150400.4.137.3 * typelib-1_0-JavaScriptCore-4_1-2.52.0-150400.4.137.3 * typelib-1_0-JavaScriptCore-6_0-2.52.0-150400.4.137.3 * libwebkit2gtk-4_1-0-debuginfo-2.52.0-150400.4.137.3 * webkit-jsc-6.0-debuginfo-2.52.0-150400.4.137.3 * libjavascriptcoregtk-4_1-0-2.52.0-150400.4.137.3 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.0-150400.4.137.3 * libjavascriptcoregtk-4_0-18-2.52.0-150400.4.137.3 * libwebkit2gtk-4_0-37-2.52.0-150400.4.137.3 * Read the Full Advisory
* openSUSE Leap 15.4 (noarch)
* WebKitGTK-4.1-lang-2.52.0-150400.4.137.3
* WebKitGTK-4.0-lang-2.52.0-150400.4.137.3
* WebKitGTK-6.0-lang-2.52.0-150400.4.137.3
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.0-150400.4.137.3
* webkit-jsc-4-debuginfo-2.52.0-150400.4.137.3
* typelib-1_0-JavaScriptCore-4_0-2.52.0-150400.4.137.3
* libjavascriptcoregtk-6_0-1-2.52.0-150400.4.137.3
* webkit-jsc-6.0-2.52.0-150400.4.137.3
* typelib-1_0-JavaScriptCore-4_1-2.52.0-150400.4.137.3
* typelib-1_0-JavaScriptCore-6_0-2.52.0-150400.4.137.3
* libwebkit2gtk-4_1-0-debuginfo-2.52.0-150400.4.137.3
* webkit-jsc-6.0-debuginfo-2.52.0-150400.4.137.3
* libjavascriptcoregtk-4_1-0-2.52.0-150400.4.137.3
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.0-150400.4.137.3
* libjavascriptcoregtk-4_0-18-2.52.0-150400.4.137.3
* libwebkit2gtk-4_0-37-2.52.0-150400.4.137.3
* bsc#1259934 * bsc#1259935 * bsc#1259936 * bsc#1259937 * bsc#1259938 * bsc#1259939 * bsc#1259940 * bsc#1259941 * bsc#1259942 * bsc#1259943 * bsc#1259944 * bsc#1259945 * bsc#1259946 * bsc#1259947 * bsc#1259948 * bsc#1259949 * bsc#1259950 ## References: * * * * * * * * * * * * * Read the Full Advisory
*
*
*
*
*
*
*
*
*
*
*
*
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
