webkitgtk: webkit2gtk: Out-of-bounds read was addressed with improved bounds checking
Published Jul 29, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.34%
Description
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
Affected products
-
Affected
- ≥ 0, < 17.6
-
Affected
- ≥ 0, < 16.7.9
- ≥ 0, < 17.6
-
Affected
- ≥ 0, < 14.6
-
Affected
- ≥ 0, < 17.6
-
Affected
- ≥ 0, < 1.3
-
Affected
- ≥ 0, < 10.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apple | Safari | unknown | Affected
|
| Apple | iOS and iPadOS | unknown | Affected
|
| Apple | macOS | unknown | Affected
|
| Apple | tvOS | unknown | Affected
|
| Apple | visionOS | unknown | Affected
|
| Apple | watchOS | unknown | Affected
|
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
webkitgtk4-0:2.48.3-2.el7_9
Fixed · RHSA-2025:10364
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.46.3-1.el8_10
Fixed · RHSA-2024:9636
Red Hat Enterprise Linux 8.2 Advanced Update Support
webkit2gtk3-0:2.46.3-1.el8_2
Fixed · RHSA-2024:9680
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
webkit2gtk3-0:2.46.3-1.el8_4
Fixed · RHSA-2024:9679
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
webkit2gtk3-0:2.46.3-1.el8_4
Fixed · RHSA-2024:9679
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
webkit2gtk3-0:2.46.3-1.el8_4
Fixed · RHSA-2024:9679
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
webkit2gtk3-0:2.46.3-1.el8_6
Fixed · RHSA-2024:9653
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
webkit2gtk3-0:2.46.3-1.el8_6
Fixed · RHSA-2024:9653
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
webkit2gtk3-0:2.46.3-1.el8_6
Fixed · RHSA-2024:9653
Red Hat Enterprise Linux 8.8 Extended Update Support
webkit2gtk3-0:2.46.3-1.el8_8
Fixed · RHSA-2024:9646
Red Hat Enterprise Linux 9
webkit2gtk3-0:2.46.1-2.el9_4
Fixed · RHSA-2024:8180
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
webkit2gtk3-0:2.46.1-1.el9_0
Fixed · RHSA-2024:8496
Red Hat Enterprise Linux 9.2 Extended Update Support
webkit2gtk3-0:2.46.1-1.el9_2
Fixed · RHSA-2024:8492
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | webkitgtk4-0:2.48.3-2.el7_9 | Fixed | RHSA-2025:10364 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.46.3-1.el8_10 | Fixed | RHSA-2024:9636 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | webkit2gtk3-0:2.46.3-1.el8_2 | Fixed | RHSA-2024:9680 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | webkit2gtk3-0:2.46.3-1.el8_4 | Fixed | RHSA-2024:9679 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | webkit2gtk3-0:2.46.3-1.el8_4 | Fixed | RHSA-2024:9679 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | webkit2gtk3-0:2.46.3-1.el8_4 | Fixed | RHSA-2024:9679 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | webkit2gtk3-0:2.46.3-1.el8_6 | Fixed | RHSA-2024:9653 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | webkit2gtk3-0:2.46.3-1.el8_6 | Fixed | RHSA-2024:9653 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | webkit2gtk3-0:2.46.3-1.el8_6 | Fixed | RHSA-2024:9653 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | webkit2gtk3-0:2.46.3-1.el8_8 | Fixed | RHSA-2024:9646 |
| Red Hat Enterprise Linux 9 | webkit2gtk3-0:2.46.1-2.el9_4 | Fixed | RHSA-2024:8180 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | webkit2gtk3-0:2.46.1-1.el9_0 | Fixed | RHSA-2024:8496 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | webkit2gtk3-0:2.46.1-1.el9_2 | Fixed | RHSA-2024:8492 |
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this flaw, an attacker needs to trick a user into processing or loading malicious web content.
Red Hat mitigation
Do not process or load untrusted web content with WebKitGTK.
References (34)
- http://seclists.org/fulldisclosure/2024/Jul/15 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/16 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/17 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/18 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/21 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/22 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/23 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-40779 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2302070 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-38620 Advisory
- https://lists.debian.org/debian-lts-announce/2024/09/msg00006.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-40779
- https://support.apple.com/en-us/120908
- https://support.apple.com/en-us/120909
- https://support.apple.com/en-us/120911
- https://support.apple.com/en-us/120913
- https://support.apple.com/en-us/120914
- https://support.apple.com/en-us/120915
- https://support.apple.com/en-us/120916
- https://support.apple.com/en-us/HT214116 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT214117 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT214119 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT214121 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT214122 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT214123 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT214124 Release NotesVendor Advisory
- https://support.apple.com/kb/HT214116
- https://support.apple.com/kb/HT214117
- https://support.apple.com/kb/HT214119
- https://support.apple.com/kb/HT214122
- https://support.apple.com/kb/HT214123
- https://support.apple.com/kb/HT214124
- https://webkitgtk.org/security/WSA-2024-0004.html#CVE-2024-40779
- https://www.cve.org/CVERecord?id=CVE-2024-40779
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data