webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
Published Mar 6, 2023 ·Due Jun 13, 2022
8.8
HIGHCVSS 3.1
EPSS 1.56%
Description
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
Affected products
- Vendor n/a Product Webkitgtk Defaultn/a
- Version Fixed in webkitgtk 2.26.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Webkitgtk | n/a |
|
Configuration 1
- < 2.26.0
- < 2.26.0
Configuration 2
- 8.0
- 8.4
- 8.6
- 8.0
- 8.4
- 8.6
- 8.0
- 8.4
- 8.6
- 8.0
- 8.4
- 8.6
- 8.0
- 7.0
- 8.4
- 8.4
- 8.6
- 8.6
- 8.6
- 7.0
- 8.0
- 8.4
- 8.6
- 7.0
- 7.0
- 8.0
- 8.4
- 8.6
- 7.0
- 7.0
- 8.4
- 8.6
- 8.4
- 8.6
- 8.4
- 8.6
- 8.4
- 8.6
- 7.0
No data.
Red Hat Enterprise Linux 7
webkitgtk4-0:2.28.2-2.el7
Fixed · RHSA-2020:4035
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.28.4-1.el8
Fixed · RHSA-2020:4451
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | webkitgtk4-0:2.28.2-2.el7 | Fixed | RHSA-2020:4035 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.28.4-1.el8 | Fixed | RHSA-2020:4451 |
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is rated as 'Moderate' as the WebKitGTK package is shipped as a dependency for the Gnome package. Red Hat Enterprise Linux does not ship any WebKitGTK-based web browser where this flaw would present a higher severity major threat.
Red Hat mitigation
Red Hat has investigated whether possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
Date Added
May 23, 2022
Patch Due
Jun 13, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jan 28, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.56% (0.01556) | 74.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.56% (0.01556) | 71.86th | v5 (v2026.06.15) |
| Jun 3, 2026 | 4.12% (0.04121) | 88.82th | v4 (v2025.03.14) |
| May 27, 2026 | 3.08% (0.03077) | 86.95th | v4 (v2025.03.14) |
| Mar 22, 2026 | 4.10% (0.04099) | 88.48th | v4 (v2025.03.14) |
| Nov 21, 2025 | 7.84% (0.07842) | 91.63th | v4 (v2025.03.14) |
| Nov 18, 2025 | 5.10% (0.05095) | 88.78th | v4 (v2025.03.14) |
| Jun 21, 2025 | 8.24% (0.08241) | 91.79th | v4 (v2025.03.14) |
| Mar 30, 2025 | 13.53% (0.13534) | 93.61th | v4 (v2025.03.14) |
| Mar 29, 2025 | 35.57% (0.35568) | 95.47th | v4 (v2025.03.14) |
| Mar 17, 2025 | 13.53% (0.13534) | 93.68th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.63% (0.00633) | 79.78th | v3 (v2023.03.01) |
| Apr 7, 2024 | 0.71% (0.00706) | 80.01th | v3 (v2023.03.01) |
| Mar 12, 2024 | 0.61% (0.00606) | 78.06th | v3 (v2023.03.01) |
| Feb 4, 2024 | 0.57% (0.00566) | 75.47th | v3 (v2023.03.01) |
| Oct 13, 2023 | 0.58% (0.00576) | 75.47th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.56% (0.00561) | 74.61th | v3 (v2023.03.01) |
| May 8, 2023 | 0.64% (0.00638) | 76.03th | v3 (v2023.03.01) |
| Mar 11, 2023 | 0.46% (0.00455) | 71.33th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.45% (0.01447) | 84.57th | v3 (v2023.03.01) |
References (7)
- https://access.redhat.com/security/cve/CVE-2019-8720 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1876611 Issue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-8720
- https://webkitgtk.org/security/WSA-2019-0005.html Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8720 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2019-8720
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-8720 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1876611 | Issue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-8720 | ||
| https://webkitgtk.org/security/WSA-2019-0005.html | Vendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8720 | government-resourceUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2019-8720 |
Change history (0)
No recorded changes yet.