CVE-2023-38592

high
Published 2023-11-07 Β· Modified 2023-11-14
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

Important: webkit2gtk3 security and bug fix update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description webkitgtk: Processing web content may lead to arbitrary code execution CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7 Extended Lifecycle Supportwebkitgtk4-0:2.48.3-2.el7_9RHSA-2025:103642025-07-07T00:00:00Z Red Hat Enterprise Linux…

Description

webkitgtk: Processing web content may lead to arbitrary code execution

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7 Extended Lifecycle Supportwebkitgtk4-0:2.48.3-2.el7_9RHSA-2025:103642025-07-07T00:00:00Z
Red Hat Enterprise Linux 8webkit2gtk3-0:2.40.5-1.el8RHSA-2023:70552023-11-14T00:00:00Z
Red Hat Enterprise Linux 9webkit2gtk3-0:2.40.5-1.el9RHSA-2023:65352023-11-07T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6webkitgtkOut of support scope
Red Hat Enterprise Linux 7webkitgtk3Affected

Apply commands

bash fix
Apply RHSA-2025:10364 for Red Hat Enterprise Linux 7 Extended Lifecycle Support
yum update -y webkitgtk4
# or:
dnf upgrade -y webkitgtk4

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 7Affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
debian debianbookwormfixed2.40.5-1~deb12u1
debian debianbullseyefixed2.40.5-1~deb11u1
debian debianforkyfixed2.40.5-1
debian debiansidfixed2.40.5-1
debian debiantrixiefixed2.40.5-1
almalinux almalinux9fixedwebkit2gtk3-jsc-devel-2.40.5-1.el9.aarch64.rpm

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.