webkitgtk: Memory corruption leading to arbitrary code execution
Published Sep 8, 2021
8.8
HIGHCVSS 3.1
EPSS 1.94%
Description
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<14.5
- Version
-
- Version unspecifiedStatusaffectedConstraints<11.3
- Version
-
- Version unspecifiedStatusaffectedConstraints<14.5
- Version
-
- Version unspecifiedStatusaffectedConstraints<7.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apple | iOS and iPadOS | n/a |
| ||||||
| Apple | macOS | n/a |
| ||||||
| Apple | tvOS | n/a |
| ||||||
| Apple | watchOS | n/a |
|
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
webkitgtk4-0:2.48.3-2.el7_9
Fixed · RHSA-2025:10364
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.30.4-1.el8
Fixed · RHSA-2021:1586
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Out of support scope
Red Hat Enterprise Linux 9
webkit2gtk3
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | webkitgtk4-0:2.48.3-2.el7_9 | Fixed | RHSA-2025:10364 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.30.4-1.el8 | Fixed | RHSA-2021:1586 |
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | webkit2gtk3 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2021-1817 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1986852 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2021-1817
- https://support.apple.com/en-us/HT212317 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT212323 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT212324 x_refsource_MISCVendor Advisory
- https://support.apple.com/en-us/HT212325 x_refsource_MISCVendor Advisory
- https://webkitgtk.org/security/WSA-2021-0004.html
- https://www.cve.org/CVERecord?id=CVE-2021-1817
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-1817 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1986852 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-1817 | ||
| https://support.apple.com/en-us/HT212317 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT212323 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT212324 | x_refsource_MISCVendor Advisory | |
| https://support.apple.com/en-us/HT212325 | x_refsource_MISCVendor Advisory | |
| https://webkitgtk.org/security/WSA-2021-0004.html | ||
| https://www.cve.org/CVERecord?id=CVE-2021-1817 |
Change history (0)
No recorded changes yet.