{"id":"SUSE-SU-2026:1139-1","summary":"Security update for webkit2gtk3","details":"This update for webkit2gtk3 fixes the following issues:\n\nUpdate to version 2.52.0:\n\n- CVE-2023-43010: processing maliciously crafted web content may lead to memory corruption (bsc#1259950).\n- CVE-2025-31223: processing maliciously crafted web content may lead to memory corruption (bsc#1259949).\n- CVE-2025-31277: processing maliciously crafted web content may lead to memory corruption (bsc#1259948).\n- CVE-2025-43213: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259947).\n- CVE-2025-43214: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259946).\n- CVE-2025-43433: processing maliciously crafted web content may lead to memory corruption (bsc#1259945).\n- CVE-2025-43438: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259944).\n- CVE-2025-43441: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259943).\n- CVE-2025-43457: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259942).\n- CVE-2025-43511: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259941).\n- CVE-2025-46299: processing maliciously crafted web content may disclose internal states of an app (bsc#1259940).\n- CVE-2026-20608: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259939).\n- CVE-2026-20635: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259938).\n- CVE-2026-20636: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259937).\n- CVE-2026-20644: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259936).\n- CVE-2026-20652: a remote attacker may be able to cause a denial-of-service (bsc#1259935).\n- CVE-2026-20676: a website may be able to track users through web extensions (bsc#1259934).\n\nChangelog:\n\n + Make scrolling with touch input smoother for small movements.\n + Fix estimated load progress of downloads when Content-Length\n value is wrong.\n + Ensure that 'scrollend' events are correctly emitted after\n scroll animations.\n + Fix several crashes and rendering issues.\n","modified":"2026-03-31T08:00:18.341974Z","published":"2026-03-30T09:13:58Z","related":["CVE-2023-42843","CVE-2023-43010","CVE-2024-54658","CVE-2025-13502","CVE-2025-31223","CVE-2025-31277","CVE-2025-43213","CVE-2025-43214","CVE-2025-43368","CVE-2025-43419","CVE-2025-43433","CVE-2025-43434","CVE-2025-43438","CVE-2025-43440","CVE-2025-43441","CVE-2025-43443","CVE-2025-43457","CVE-2025-43511","CVE-2025-46299","CVE-2026-20608","CVE-2026-20635","CVE-2026-20636","CVE-2026-20644","CVE-2026-20652","CVE-2026-20676"],"upstream":["CVE-2023-42843","CVE-2023-43010","CVE-2024-54658","CVE-2025-13502","CVE-2025-31223","CVE-2025-31277","CVE-2025-43213","CVE-2025-43214","CVE-2025-43368","CVE-2025-43419","CVE-2025-43433","CVE-2025-43434","CVE-2025-43438","CVE-2025-43440","CVE-2025-43441","CVE-2025-43443","CVE-2025-43457","CVE-2025-43511","CVE-2025-46299","CVE-2026-20608","CVE-2026-20635","CVE-2026-20636","CVE-2026-20644","CVE-2026-20652","CVE-2026-20676"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261139-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259934"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259936"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259937"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259940"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259942"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259943"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259944"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259947"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42843"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-43010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-54658"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-13502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31223"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-31277"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43368"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43419"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43433"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43434"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43438"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43440"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43443"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43511"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-46299"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20608"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20635"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20636"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20644"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20652"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-20676"}],"affected":[{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.52.0-4.54.1"}]}],"ecosystem_specific":{"binaries":[{"libwebkit2gtk3-lang":"2.52.0-4.54.1","typelib-1_0-JavaScriptCore-4_0":"2.52.0-4.54.1","typelib-1_0-WebKit2-4_0":"2.52.0-4.54.1","typelib-1_0-WebKit2WebExtension-4_0":"2.52.0-4.54.1","webkit2gtk-4_0-injected-bundles":"2.52.0-4.54.1","webkit2gtk3-devel":"2.52.0-4.54.1","libjavascriptcoregtk-4_0-18":"2.52.0-4.54.1","libwebkit2gtk-4_0-37":"2.52.0-4.54.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1139-1.json"}},{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.52.0-4.54.1"}]}],"ecosystem_specific":{"binaries":[{"webkit2gtk-4_0-injected-bundles":"2.52.0-4.54.1","webkit2gtk3-devel":"2.52.0-4.54.1","libjavascriptcoregtk-4_0-18":"2.52.0-4.54.1","libwebkit2gtk-4_0-37":"2.52.0-4.54.1","libwebkit2gtk3-lang":"2.52.0-4.54.1","typelib-1_0-JavaScriptCore-4_0":"2.52.0-4.54.1","typelib-1_0-WebKit2-4_0":"2.52.0-4.54.1","typelib-1_0-WebKit2WebExtension-4_0":"2.52.0-4.54.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1139-1.json"}}],"schema_version":"1.7.5"}