Linuxsecurity SUSE Addresses Multiple Critical Vulnerabilities in Webkit2gtk3 and Libheif
Article Content
- •SUSE patched critical vulnerabilities in webkit2gtk3 and libheif affecting multiple systems.
- •CVE-2026-28847 allows for arbitrary code execution via a heap buffer overflow.
- •Immediate patching is recommended to prevent potential exploitation of these vulnerabilities.
SUSE has released important updates for webkit2gtk3 and libheif to address multiple vulnerabilities. The webkit2gtk3 update (version 2.52.4) fixes five CVEs, including CVE-2026-28847, which can lead to arbitrary code execution due to a heap buffer overflow. The libheif update (version 1.23.0) resolves seven CVEs, such as CVE-2026-32740, which involves a heap buffer overflow that could lead to denial of service. Both updates are critical for users relying on these libraries, as they involve processing maliciously crafted content that could crash applications or allow unauthorized access. Users are advised to apply the patches immediately to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2025-68431 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…