Impact
A flaw in WebKitGTK causes a use‑after‑free when malicious web content is processed, leading to memory corruption that may allow arbitrary code execution. The bug stems from improper memory handling of jscvalue function parameters and is catalogued as CWE‑416.
Affected Systems
Red Hat Enterprise Linux 6 through 9 are affected because the platform includes WebKitGTK. Packages that depend on WebKitGTK4 – such as evolution‑data‑server, glade, gnome‑boxes, gnome‑initial‑setup, gnome‑online‑accounts, gnome‑shell, shotwell, sushi, and yelp – must be present for the vulnerability to be exploitable. WebKitGTK3 is not required by any installed package and may be removed without impacting functionality.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity flaw, and it has not been listed in the CISA KEV catalog. Exploitation requires the presence of the vulnerable packages and the use of a graphical interface to load untrusted content; in gnome‑shell, a local network attacker can achieve this without user interaction. Because no EPSS score is available, the current exploitation probability cannot be quantified, but the high severity and local‑network attack vector warrant prompt action.
OpenCVE Enrichment