Red Hat Enterprise Linux 7 update for webkitgtk4

This security bulletin contains one critical risk vulnerability.


1) Use-after-free


EUVDB-ID: #VU56475


Risk: Critical


CVSSv3.1: 8.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C]


CVE-ID: CVE-2021-30858


CWE-ID: CWE-416 - Use After Free


Exploit availability: Yes


Description

The vulnerability allows a remote attacker to compromise vulnerable system.


The vulnerability exists due to a use-after-free error when processing HTML content in WebKit. A remote attacker can trick the victim to visit a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the system.


Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Note, the vulnerability is being actively exploited in-the-wild.


Mitigation

Install updates from vendor's website.


Vulnerable software versions

webkitgtk4 (Red Hat package): 2.28.2-2.el7


Red Hat Enterprise Linux for Power, little endian: 7


Red Hat Enterprise Linux for Power, big endian: 7


Red Hat Enterprise Linux for IBM z Systems: 7


Red Hat Enterprise Linux for Scientific Computing: 7


Red Hat Enterprise Linux Desktop: 7


Red Hat Enterprise Linux Workstation: 7


Red Hat Enterprise Linux Server: 7


CPE2.3
External links

< ..

Support the originator by clicking the read the rest link below.