CVE-2021-42762
Summary
| CVE | CVE-2021-42762 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-20 19:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 33 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Application | Webkitgtk | Webkitgtk | All | All | All | All |
| Application | Wpewebkit | Wpe Webkit | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006 | MLIST | www.openwall.com | |
| 231479 – [WPE][GTK] Limited sandbox escape via VFS syscalls | MISC | bugs.webkit.org | |
| [SECURITY] Fedora 33 Update: webkit2gtk3-2.34.1-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Debian -- Security Information -- DSA-4995-1 webkit2gtk | DEBIAN | www.debian.org | |
| oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006 | MLIST | www.openwall.com | |
| [SECURITY] Fedora 34 Update: webkit2gtk3-2.34.1-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 35 Update: webkit2gtk3-2.34.1-2.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 35 Update: webkit2gtk3-2.34.1-2.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| oss-security - Re: WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006 | MLIST | www.openwall.com | |
| [SECURITY] Fedora 33 Update: webkit2gtk3-2.34.1-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| oss-security - Re: WebKitGTK and WPE WebKit Security Advisory WSA-2021-0006 | MLIST | www.openwall.com | |
| CVE-2021-41133: Sandbox bypass via recent VFS-manipulating syscalls · Advisory · flatpak/flatpak · GitHub | MISC | github.com | |
| Debian -- Security Information -- DSA-4996-1 wpewebkit | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 34 Update: webkit2gtk3-2.34.1-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178857 Debian Security Update for webkit2gtk (DSA 4995-1)
- 178858 Debian Security Update for wpewebkit (DSA 4996-1)
- 183506 Debian Security Update for webkit2gtkwpewebkit (CVE-2021-42762)
- 198555 Ubuntu Security Notification for WebKitGTK Vulnerabilities (USN-5127-1)
- 282041 Fedora Security Update for webkit2gtk3 (FEDORA-2021-483d896d1d)
- 282042 Fedora Security Update for webkit2gtk3 (FEDORA-2021-131360fa9a)
- 296061 Oracle Solaris 11.4 Support Repository Update (SRU) 42.113.1 Missing (CPUJAN2022)
- 354436 Amazon Linux Security Advisory for webkit2gtk3 : ALAS2022-2022-015
- 355438 Amazon Linux Security Advisory for webkitgtk4 : ALAS2-2023-2088
- 502199 Alpine Linux Security Update for webkit2gtk
- 710570 Gentoo Linux WebkitGTK+ Multiple Vulnerabilities (GLSA 202202-01)
- 751325 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2021:1454-1)
- 751333 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2021:3603-1)
- 751392 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2021:3769-1)
- 751394 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2021:3768-1)