Unrated severityNVD Advisory· Published Oct 20, 2021· Updated Aug 4, 2024
CVE-2021-42762
CVE-2021-42762
Description
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.
Affected products
31- Apple/WebKitGTK and WPE WebKitdescription
- osv-coords30 versionspkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/webkit2gtk3&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 2.32.4-lp152.2.22.1+ 29 more
- (no CPE)range: < 2.32.4-lp152.2.22.1
- (no CPE)range: < 2.32.4-15.1
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.32.4-15.1
- (no CPE)range: < 2.32.4-15.1
- (no CPE)range: < 2.32.4-15.1
- (no CPE)range: < 2.32.4-15.1
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.34.1-3.87.1
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
- (no CPE)range: < 2.32.4-2.74.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H6MGXCX7P5AHWOQ6IRT477UKT7IS4DAD/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5J2LZQTDX53DNSKSGU7TQYCO2HKSTY4/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ON5SDVVPVPCAGFPW2GHYATZVZYLPW2L4/mitrevendor-advisoryx_refsource_FEDORA
- www.debian.org/security/2021/dsa-4995mitrevendor-advisoryx_refsource_DEBIAN
- www.debian.org/security/2021/dsa-4996mitrevendor-advisoryx_refsource_DEBIAN
- www.openwall.com/lists/oss-security/2021/10/26/9mitremailing-listx_refsource_MLIST
- www.openwall.com/lists/oss-security/2021/10/27/1mitremailing-listx_refsource_MLIST
- www.openwall.com/lists/oss-security/2021/10/27/2mitremailing-listx_refsource_MLIST
- www.openwall.com/lists/oss-security/2021/10/27/4mitremailing-listx_refsource_MLIST
- bugs.webkit.org/show_bug.cgimitrex_refsource_MISC
- github.com/flatpak/flatpak/security/advisories/GHSA-67h7-w3jq-vh4qmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.