SUSE-SU-2024:1269-1

Advisory lineage Upstream: 8 Downstream: 0
Published: 12 Apr 2024, 13:34
Last modified:04 Feb 2026, 03:57

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Apr 2024, 13:34
Published
Vulnerability first disclosed
04 Feb 2026, 03:57
Last Modified
Vulnerability information updated

Description

Security update for webkit2gtk3 This update for webkit2gtk3 fixes the following issues: - CVE-2024-23252: Fixed denial of service via crafted web content (bsc#1222010). - CVE-2024-23254: Fixed possible audio data exilftration cross-origin via malicious website (bsc#1222010). - CVE-2024-23263: Fixed lack of Content Security Policy enforcing via malicious crafted web content (bsc#1222010). - CVE-2024-23280: Fixed possible user fingeprint via malicious crafted web content (bsc#1222010). - CVE-2024-23284: Fixed lack of Content Security Policy enforcing via malicious crafted web content (bsc#1222010). - CVE-2023-42950: Fixed arbitrary code execution via crafted web content (bsc#1222010). - CVE-2023-42956: Fixed denial of service via crafted web content (bsc#1222010). - CVE-2023-42843: Fixed address bar spoofing via malicious website (bsc#1222010). Other fixes: - Update to version 2.44.0 (bsc#1222010): + Make the DOM accessibility tree reachable from UI process with GTK4. + Removed the X11 and WPE renderers in favor of DMA-BUF. + Improved vblank synchronization when rendering. + Removed key event reinjection in GTK4 to make keyboard shortcuts work in web sites. + Fix gamepads detection by correctly handling focused window in GTK4.

Affected Systems

  • susewebkit2gtk3&distro=SUSE Enterprise Storage 7.1

    < 2.44.0-150200.107.1

  • susewebkit2gtk3&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 2.44.0-150200.107.1

  • susewebkit2gtk3&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 2.44.0-150200.107.1

  • susewebkit2gtk3&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 2.44.0-150200.107.1

  • susewebkit2gtk3&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 2.44.0-150200.107.1

  • susewebkit2gtk3&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 2.44.0-150200.107.1

  • susewebkit2gtk3&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 2.44.0-150200.107.1

References (10)