Security restrictions bypass in WebKitGTK+ and WPE WebKit - CVE-2021-42762
Published: November 1, 2021
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists in BubblewrapLauncher.cpp due to application allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox. A local user can abuse the VFS syscalls that manipulate its filesystem namespace and bypass implemented security restrictions. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined.
Affected software
WPE WebKit
Arch Linux
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Desktop Applications
Ubuntu
Fedora
webkit2gtk (Debian package)
wpewebkit (Debian package)
webkit2gtk3-devel
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk-4_0-injected-bundles
typelib-1_0-WebKit2WebExtension-4_0
typelib-1_0-WebKit2-4_0
typelib-1_0-JavaScriptCore-4_0
libwebkit2gtk-4_0-37-debuginfo
libwebkit2gtk-4_0-37
libjavascriptcoregtk-4_0-18-debuginfo
libjavascriptcoregtk-4_0-18
libwebkit2gtk3-lang
webkit2gtk3-debugsource
libjavascriptcoregtk-4.0-18 (Ubuntu package)
libwebkit2gtk-4.0-37 (Ubuntu package)
wpewebkit
webkit2gtk
webkit2gtk3
webkitgtk4 (Red Hat package)
How to mitigate CVE-2021-42762
WPE WebKit - update to 2.34.1
webkit2gtk (Debian package) - addressed in versions 2.34.1-1~deb10u1, 2.34.1-1~deb11u1
wpewebkit (Debian package) - update to 2.34.1-1~deb11u1
webkit2gtk3-devel - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
webkit2gtk-4_0-injected-bundles-debuginfo - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
webkit2gtk-4_0-injected-bundles - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
typelib-1_0-WebKit2WebExtension-4_0 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
typelib-1_0-WebKit2-4_0 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
typelib-1_0-JavaScriptCore-4_0 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libwebkit2gtk-4_0-37-debuginfo - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libwebkit2gtk-4_0-37 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libjavascriptcoregtk-4_0-18-debuginfo - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libjavascriptcoregtk-4_0-18 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libwebkit2gtk3-lang - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
webkit2gtk3-debugsource - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libjavascriptcoregtk-4.0-18 (Ubuntu package) - addressed in versions 2.34.1-0ubuntu0.20.04.1, 2.34.1-0ubuntu0.21.04.1, 2.34.1-0ubuntu0.21.10.1
libwebkit2gtk-4.0-37 (Ubuntu package) - addressed in versions 2.34.1-0ubuntu0.20.04.1, 2.34.1-0ubuntu0.21.04.1, 2.34.1-0ubuntu0.21.10.1
wpewebkit - update to 2.34.1-1
webkit2gtk - update to 2.34.1-1
webkit2gtk3 - addressed in versions 2.34.1-1.fc33, 2.34.1-1.fc34, 2.34.1-1.fc35, 2.34.1-2.fc35
webkitgtk4 (Red Hat package) - update to 2.48.3-2.el7_9
External References
- https://bugs.webkit.org/show_bug.cgi?id=231479
- https://github.com/flatpak/flatpak/security/advisories/GHSA-67h7-w3jq-vh4q
- http://www.openwall.com/lists/oss-security/2021/10/26/9
- http://www.openwall.com/lists/oss-security/2021/10/27/1
- http://www.openwall.com/lists/oss-security/2021/10/27/2
- http://www.openwall.com/lists/oss-security/2021/10/27/4
- https://www.debian.org/security/2021/dsa-4996
- https://www.debian.org/security/2021/dsa-4995
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M5J2LZQTDX53DNSKSGU7TQYCO2HKSTY4/
Related Security Bulletins
- Multiple vulnerabilities in WebKitGTK+ and WPE WebKit
- Debian update for webkit2gtk
- Debian update for wpewebkit
- Gentoo update for WebkitGTK+
- SUSE update for webkit2gtk3
- SUSE update for webkit2gtk3
- SUSE update for webkit2gtk3
- Ubuntu update for webkit2gtk
- Arch Linux update for wpewebkit
- Arch Linux update for webkit2gtk
- Fedora 33 update for webkit2gtk3
- Fedora 34 update for webkit2gtk3
- Fedora 35 update for webkit2gtk3
- Fedora 35 update for webkit2gtk3
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for webkitgtk4