{"id":"SUSE-SU-2025:02973-1","summary":"Security update for webkit2gtk3","details":"This update for webkit2gtk3 fixes the following issues:\n\n- Update to version 2.48.5: \n  + CVE-2025-31273: Fixed processing maliciously crafted web content leading to memory corruption (bsc#1247564)\n  + CVE-2025-43265: Fixed processing maliciously crafted web content disclosing internal states of the app (bsc#1247600)\n  + CVE-2025-43216: Fixed processing maliciously crafted web content leading to an unexpected Safari crash (bsc#1247596)\n  + CVE-2025-31278: Fixed processing maliciously crafted web content leading to memory corruption (bsc#1247563)\n  + CVE-2025-6558: Fixed processing maliciously crafted web content leading to an unexpected Safari crash. (bsc#1247742)\n  + CVE-2025-43227: Fixed Processing maliciously crafted web content disclosing sensitive user information (bsc#1247597)\n  + CVE-2025-43240: Fixed download’s origin incorrectly associated (bsc#1247599)\n  + CVE-2025-43228: Fixed visiting a malicious website leading to address bar spoofing (bsc#1247598)\n  + CVE-2025-43212: Fixed processing maliciously crafted web content leading to an unexpected Safari crash (bsc#1247595)\n  + CVE-2025-43211: Fixed processing web content leading to a denial-of-service (bsc#1247562) \n  + Fix several crashes.\n  + Changes in version 2.48.4:\n  + Improve emoji font selection with USE_SKIA=ON.\n  + Improve playback of multimedia streams from blob URLs.\n  + Fix the build with USE_SKIA_OPENTYPE_SVG=ON and\n    USE_SYSPROF_CAPTURE=ON.\n  + Fix the build on LoongArch with USE_SKIA=ON.\n  + Fix crash when using a WebKitWebView widget in an offscreen\n    window.\n  + Fix several crashes and rendering issues.\n  + Changes in version 2.48.3:\n  + Fix a crash introduced by the new threaded rendering\n    implementation using Skia API.\n  + Improve rendering performance by recording layers once and\n    replaying every dirty region in different worker threads.\n  + Fix a crash when setting WEBKIT_SKIA_GPU_PAINTING_THREADS=0.\n  + Fix a reference cycle in webkitmediastreamsrc preventing its\n    disposal.\n\n- CVE-2024-44192:Fixed processing maliciously crafted web content leading to an unexpected process crash (bsc#1239863)\n- CVE-2024-54467: Fixed data cross-origin exfiltration due to a cookie management issue (bsc#1239864)\n- CVE-2025-24201: Fixed out-of-bounds write vulnerability (bsc#1239547)\n- CVE-2025-24189: Fixed processing maliciously crafted web content leading to memory corruption (bsc#1247565)\n  ","modified":"2026-03-11T07:29:11.092976Z","published":"2025-08-25T08:49:16Z","related":["CVE-2024-44192","CVE-2024-54467","CVE-2025-24189","CVE-2025-24201","CVE-2025-31273","CVE-2025-31278","CVE-2025-43211","CVE-2025-43212","CVE-2025-43216","CVE-2025-43227","CVE-2025-43228","CVE-2025-43240","CVE-2025-43265","CVE-2025-6558"],"upstream":["CVE-2024-44192","CVE-2024-54467","CVE-2025-24189","CVE-2025-24201","CVE-2025-31273","CVE-2025-31278","CVE-2025-43211","CVE-2025-43212","CVE-2025-43216","CVE-2025-43227","CVE-2025-43228","CVE-2025-43240","CVE-2025-43265","CVE-2025-6558"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202502973-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239547"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239863"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239864"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247562"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247563"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247564"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247565"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247596"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247597"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247599"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247600"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247742"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-44192"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-54467"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-24189"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-24201"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31273"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31278"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43211"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43212"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43228"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43240"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43265"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-6558"}],"affected":[{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.48.5-4.41.1"}]}],"ecosystem_specific":{"binaries":[{"libwebkit2gtk-4_0-37":"2.48.5-4.41.1","libwebkit2gtk3-lang":"2.48.5-4.41.1","typelib-1_0-JavaScriptCore-4_0":"2.48.5-4.41.1","typelib-1_0-WebKit2-4_0":"2.48.5-4.41.1","typelib-1_0-WebKit2WebExtension-4_0":"2.48.5-4.41.1","webkit2gtk-4_0-injected-bundles":"2.48.5-4.41.1","webkit2gtk3-devel":"2.48.5-4.41.1","libjavascriptcoregtk-4_0-18":"2.48.5-4.41.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02973-1.json"}},{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.48.5-4.41.1"}]}],"ecosystem_specific":{"binaries":[{"typelib-1_0-JavaScriptCore-4_0":"2.48.5-4.41.1","typelib-1_0-WebKit2-4_0":"2.48.5-4.41.1","typelib-1_0-WebKit2WebExtension-4_0":"2.48.5-4.41.1","webkit2gtk-4_0-injected-bundles":"2.48.5-4.41.1","webkit2gtk3-devel":"2.48.5-4.41.1","libjavascriptcoregtk-4_0-18":"2.48.5-4.41.1","libwebkit2gtk-4_0-37":"2.48.5-4.41.1","libwebkit2gtk3-lang":"2.48.5-4.41.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02973-1.json"}}],"schema_version":"1.7.5"}