Linuxsecurity Critical Vulnerabilities in webkit2gtk3 Affecting openSUSE and SUSE Systems
Article Content
- •Multiple critical vulnerabilities in webkit2gtk3 require immediate patching.
- •CVE-2025-31277 is actively exploited, increasing urgency for updates.
- •Affected systems include openSUSE Leap 15.4 and various SUSE Linux Enterprise versions.
A significant update for webkit2gtk3 has been released to address multiple vulnerabilities, including CVE-2023-43010, CVE-2025-31223, CVE-2025-31277, CVE-2025-43213, CVE-2025-43214, CVE-2025-43433, CVE-2025-43438, and CVE-2025-43441. These vulnerabilities can lead to memory corruption and unexpected crashes when processing maliciously crafted web content. The update is crucial for users of openSUSE Leap 15.4 and SUSE Linux Enterprise systems. The vulnerabilities were disclosed between 2023 and 2025, with some being actively exploited, particularly CVE-2025-31277, which was added to the CISA KEV list on March 20, 2026. The patch is available through standard SUSE installation methods. Users are urged to apply the update promptly to mitigate potential risks. The overall impact is significant, affecting a wide range of systems reliant on webkit2gtk3.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track OpenSUSE and CVE-2023-42843 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…