SUSE Addresses Multiple Critical Vulnerabilities in Webkit2gtk3 and Libheif

SUSE Addresses Multiple Critical Vulnerabilities in Webkit2gtk3 and Libheif

8h ago Linuxsecurity 78% similarity 72.0
Share:

Article Content

Browse articles
ThreatCluster

SUSE has released important updates for webkit2gtk3 and libheif to address multiple vulnerabilities. The webkit2gtk3 update (version 2.52.4) fixes five CVEs, including CVE-2026-28847, which can lead to arbitrary code execution due to a heap buffer overflow. The libheif update (version 1.23.0) resolves seven CVEs, such as CVE-2026-32740, which involves a heap buffer overflow that could lead to denial of service. Both updates are critical for users relying on these libraries, as they involve processing maliciously crafted content that could crash applications or allow unauthorized access. Users are advised to apply the patches immediately to mitigate these risks.

Key Points: • SUSE patched critical vulnerabilities in webkit2gtk3 and libheif affecting multiple systems. • CVE-2026-28847 allows for arbitrary code execution via a heap buffer overflow. • Immediate patching is recommended to prevent potential exploitation of these vulnerabilities.

ThreatCluster AI

Timeline

2025-12-29
CVE-2025-68431 published for libheif
A heap buffer over-read vulnerability in libheif was disclosed, affecting image processing capabilities.
Linuxsecurity
2026-03-11
CVE-2026-3950 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
Multiple CVEs published for webkit2gtk3
CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, and CVE-2026-28903 were disclosed, highlighting serious memory handling issues.
Linuxsecurity
2026-05-11
CVE-2026-28847 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28901 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28903 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28902 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-11
CVE-2026-28883 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-19
Multiple CVEs published for libheif
CVE-2026-32740, CVE-2026-32739, CVE-2026-32738, CVE-2026-32741, and CVE-2026-32814 were disclosed, indicating serious vulnerabilities.
Linuxsecurity
2026-05-19
CVE-2026-32740 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →