CVE-2020-10018: Use After Free
accessibility/AXObjectCache.cpp in WebKit, as used in WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4, allows a denial of service (application crash) because maintenance of the mdeferredFocusedNodeChange data structure mishandles removal.
Upstream patch:
https://trac.webkit.org/changeset/257292/webkit
Other sources
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10018?
CVE-2020-10018 is a memory corruption vulnerability in WebKitGTK and WPE WebKit versions before 2.28.0.
How severe is CVE-2020-10018?
CVE-2020-10018 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
What is the impact of CVE-2020-10018?
CVE-2020-10018 may lead to arbitrary code execution.
How can I fix CVE-2020-10018?
CVE-2020-10018 has been fixed in version 2.28.0 of WebKitGTK and WPE WebKit with improved memory handling.
Where can I find more information about CVE-2020-10018?
More information about CVE-2020-10018 can be found at the following references: [CVE-2020-10018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10018), [WebKit Changeset](https://trac.webkit.org/changeset/257292), [WebKitGTK Security Advisory](https://webkitgtk.org/security/WSA-2020-0003.html).