Security restrictions bypass in WebKitGTK+ and WPE WebKit - CVE-2021-42762

 

Security restrictions bypass in WebKitGTK+ and WPE WebKit - CVE-2021-42762

Published: November 1, 2021


Vulnerability identifier: #VU57811
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42762
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists in BubblewrapLauncher.cpp due to application allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox. A local user can abuse the VFS syscalls that manipulate its filesystem namespace and bypass implemented security restrictions. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined.


Affected software

WebKitGTK+
WPE WebKit
Arch Linux
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Desktop Applications
Ubuntu
Fedora
webkit2gtk (Debian package)
wpewebkit (Debian package)
webkit2gtk3-devel
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk-4_0-injected-bundles
typelib-1_0-WebKit2WebExtension-4_0
typelib-1_0-WebKit2-4_0
typelib-1_0-JavaScriptCore-4_0
libwebkit2gtk-4_0-37-debuginfo
libwebkit2gtk-4_0-37
libjavascriptcoregtk-4_0-18-debuginfo
libjavascriptcoregtk-4_0-18
libwebkit2gtk3-lang
webkit2gtk3-debugsource
libjavascriptcoregtk-4.0-18 (Ubuntu package)
libwebkit2gtk-4.0-37 (Ubuntu package)
wpewebkit
webkit2gtk
webkit2gtk3
webkitgtk4 (Red Hat package)

How to mitigate CVE-2021-42762

Install updates from vendor's website.

WebKitGTK+ - update to 2.34.1
WPE WebKit - update to 2.34.1
webkit2gtk (Debian package) - addressed in versions 2.34.1-1~deb10u1, 2.34.1-1~deb11u1
wpewebkit (Debian package) - update to 2.34.1-1~deb11u1
webkit2gtk3-devel - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
webkit2gtk-4_0-injected-bundles-debuginfo - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
webkit2gtk-4_0-injected-bundles - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
typelib-1_0-WebKit2WebExtension-4_0 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
typelib-1_0-WebKit2-4_0 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
typelib-1_0-JavaScriptCore-4_0 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libwebkit2gtk-4_0-37-debuginfo - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libwebkit2gtk-4_0-37 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libjavascriptcoregtk-4_0-18-debuginfo - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libjavascriptcoregtk-4_0-18 - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libwebkit2gtk3-lang - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
webkit2gtk3-debugsource - addressed in versions 2.32.4-2.74.5, 2.32.4-15.1, 2.34.1-3.87.1
libjavascriptcoregtk-4.0-18 (Ubuntu package) - addressed in versions 2.34.1-0ubuntu0.20.04.1, 2.34.1-0ubuntu0.21.04.1, 2.34.1-0ubuntu0.21.10.1
libwebkit2gtk-4.0-37 (Ubuntu package) - addressed in versions 2.34.1-0ubuntu0.20.04.1, 2.34.1-0ubuntu0.21.04.1, 2.34.1-0ubuntu0.21.10.1
wpewebkit - update to 2.34.1-1
webkit2gtk - update to 2.34.1-1
webkit2gtk3 - addressed in versions 2.34.1-1.fc33, 2.34.1-1.fc34, 2.34.1-1.fc35, 2.34.1-2.fc35
webkitgtk4 (Red Hat package) - update to 2.48.3-2.el7_9

External References

Related Security Bulletins