CVE-2023-2203

HIGH

WebKitGTK - Use-After-Free via Specially Crafted Web Content

Title source: llm
STIX 2.1

Description

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

References (4)

Core 4

Scores

CVSS v3 8.8
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (9)
redhat/enterprise_linux 8.0
redhat/enterprise_linux 9.0
redhat/enterprise_linux_eus 8.8
redhat/enterprise_linux_eus 9.2
redhat/enterprise_linux_server_aus 8.8
redhat/enterprise_linux_server_aus 9.2
redhat/enterprise_linux_server_tus 8.8
webkitgtk/webkit2gtk3 2.38.5-1.el8
webkitgtk/webkit2gtk3 2.38.5-1.el9
Published May 17, 2023
Tracked Since Feb 18, 2026