The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade webkit2gtk | Aug 10, 2020 | Jul 14, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 14, 2020 |
| Debian | — | Upgrade wpewebkitUpgrade webkit2gtk | Jul 17, 2020 | Jul 14, 2020 |
| Freebsd | — | Upgrade webkit2-gtk3 | Sep 19, 2020 | Jul 10, 2020 |
| Gentoo Linux | — | Upgrade net-libs/webkit-gtk. | Jul 28, 2020 | Jul 14, 2020 |
| Oracle Solaris | — | Upgrade library/desktop/webkitgtk4 to version 2.28.4-11.4.26.0.1.75.3 on Solaris 11.4 | Jan 19, 2021 | Jul 14, 2020 |
| Redhat_linux | — | Upgrade webkitgtk4-develUpgrade webkitgtk4Upgrade webkitgtk4-jsc-develUpgrade webkitgtk4-docUpgrade webkitgtk4-jscUpgrade webkitgtk4-debuginfo | Jun 17, 2026 | Jul 10, 2020 |
| Suse | — | Upgrade typelib-1_0-webkit2webextension-4_0Upgrade webkit-jsc-4Upgrade webkit2gtk3-develUpgrade libjavascriptcoregtk-4_0-18Upgrade typelib-1_0-webkit2-4_0Upgrade libwebkit2gtk-4_0-37-32bitUpgrade libwebkit2gtk3-langUpgrade webkit2gtk3-minibrowserUpgrade typelib-1_0-javascriptcore-4_0Upgrade libwebkit2gtk-4_0-37Upgrade webkit2gtk-4_0-injected-bundlesUpgrade libjavascriptcoregtk-4_0-18-32bit | Jul 22, 2020 | Jul 14, 2020 |
| Ubuntu | — | Upgrade libjavascriptcoregtk-4.0-18Upgrade libwebkit2gtk-4.0-37 | Aug 5, 2020 | Jul 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub