Use-after-free in webkit2gtk3 (Red Hat package) - CVE-2023-2203
Published: May 9, 2023
Vulnerability identifier: #VU75918
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2203
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a missing fix for a critical risk vulnerability in WebKit #VU74604 (CVE-2023-28205). A remote attacker can trick the victim to open a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Note, the vulnerability is being actively exploited in the wild.Affected software
webkit2gtk3 (Red Hat package)
webkit2gtk3
webkit2gtk3-devel
webkit2gtk3-jsc
webkit2gtk3-jsc-devel
Oracle Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
webkit2gtk3
webkit2gtk3-devel
webkit2gtk3-jsc
webkit2gtk3-jsc-devel
Oracle Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
How to mitigate CVE-2023-2203
Install updates from vendor's website.
webkit2gtk3 (Red Hat package) - addressed in versions 2.38.5-1.el9_2.1, 2.38.5-1.el8_8.3
webkit2gtk3 - update to 2.38.5-1.0.1
webkit2gtk3-devel - update to 2.38.5-1.0.1
webkit2gtk3-jsc - update to 2.38.5-1.0.1
webkit2gtk3-jsc-devel - update to 2.38.5-1.0.1
webkit2gtk3 - update to 2.38.5-1.0.1
webkit2gtk3-devel - update to 2.38.5-1.0.1
webkit2gtk3-jsc - update to 2.38.5-1.0.1
webkit2gtk3-jsc-devel - update to 2.38.5-1.0.1