RHSA-2023:2834HighCVSS 8.8

Red Hat Security Advisory: webkit2gtk3 security and bug fix update

Published
May 16, 2023
Last Modified
June 26, 2026

🔗 CVE IDs covered (23)

📋 Description

CVE-2022-32886 — webkitgtk: buffer overflow issue was addressed with improved memory handling CVE-2022-32888 — webkitgtk: out-of-bounds write issue was addressed with improved bounds checking CVE-2022-32923 — webkitgtk: correctness issue in the JIT was addressed with improved checks CVE-2022-42799 — webkitgtk: issue was addressed with improved UI handling CVE-2022-42823 — webkitgtk: type confusion issue leading to arbitrary code execution CVE-2022-42824 — webkitgtk: sensitive information disclosure issue CVE-2022-42826 — webkitgtk: use-after-free issue leading to arbitrary code execution CVE-2022-42852 — webkitgtk: memory disclosure issue was addressed with improved memory handling CVE-2022-42863 — webkitgtk: memory corruption issue leading to arbitrary code execution CVE-2022-42867 — webkitgtk: use-after-free issue leading to arbitrary code execution CVE-2022-46691 — webkitgtk: memory corruption issue leading to arbitrary code execution CVE-2022-46692 — webkitgtk: Same Origin Policy bypass issue CVE-2022-46698 — webkitgtk: logic issue leading to user information disclosure CVE-2022-46699 — webkitgtk: memory corruption issue leading to arbitrary code execution CVE-2022-46700 — webkitgtk: memory corruption issue leading to arbitrary code execution CVE-2022-48503 — webkitgtk: improper bounds checking leading to arbitrary code execution CVE-2023-23517 — webkitgtk: memory corruption issue leading to arbitrary code execution CVE-2023-23518 — webkitgtk: memory corruption issue leading to arbitrary code execution CVE-2023-25358 — webkitgtk: heap-use-after-free in WebCore::RenderLayer::addChild() CVE-2023-25360 — webkitgtk: heap-use-after-free in WebCore::RenderLayer::renderer() CVE-2023-25361 — webkitgtk: heap-use-after-free in WebCore::RenderLayer::setNextSibling() CVE-2023-25362 — webkitgtk: heap-use-after-free in WebCore::RenderLayer::repaintBlockSelectionGaps() CVE-2023-25363 — webkitgtk: heap-use-after-free in WebCore::RenderLayer::updateDescendantDependentFlags()

🔗 References (28)