HIGH
webkitgtk: Heap buffer overflow in WebCore::TextureMapperLayer::setContentsLayer leading to arbitrary code execution
Published May 6, 2022
7.5
HIGHCVSS 3.1
EPSS 2.22%
Description
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
Affected products
No data.
Configuration 2
OR
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
webkitgtk4-0:2.48.3-2.el7_9
Fixed · RHSA-2025:10364
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.36.7-1.el8
Fixed · RHSA-2022:7704
Red Hat Enterprise Linux 9
webkit2gtk3-0:2.36.7-1.el9
Fixed · RHSA-2022:8054
Red Hat Enterprise Linux 7
webkitgtk3
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | webkitgtk4-0:2.48.3-2.el7_9 | Fixed | RHSA-2025:10364 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.36.7-1.el8 | Fixed | RHSA-2022:7704 |
| Red Hat Enterprise Linux 9 | webkit2gtk3-0:2.36.7-1.el9 | Fixed | RHSA-2022:8054 |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://www.openwall.com/lists/oss-security/2022/05/30/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-30293 Vendor Advisory
- https://bugs.webkit.org/show_bug.cgi?id=237187 x_refsource_MISCPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2082548 Issue Tracking
- https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-30293
- https://security.gentoo.org/glsa/202208-39 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-30293
- https://www.debian.org/security/2022/dsa-5154 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2022/dsa-5155 vendor-advisoryx_refsource_DEBIANThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2022/05/30/1 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2022-30293 | Vendor Advisory | |
| https://bugs.webkit.org/show_bug.cgi?id=237187 | x_refsource_MISCPatchVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2082548 | Issue Tracking | |
| https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-30293 | ||
| https://security.gentoo.org/glsa/202208-39 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-30293 | ||
| https://www.debian.org/security/2022/dsa-5154 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.debian.org/security/2022/dsa-5155 | vendor-advisoryx_refsource_DEBIANThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 6, 2022
Updated Aug 3, 2024
Reserved May 6, 2022
Link CVE-2022-30293
CISA Vulnrichment
Updated n/a