CVE-2022-30293: Buffer Overflow
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-30293?
CVE-2022-30293 is a heap-based buffer overflow vulnerability found in WebKitGTK through version 2.36.0 and WPE WebKit.
How severe is CVE-2022-30293?
CVE-2022-30293 has a severity score of 7.5, which is considered high.
Which software versions are affected by CVE-2022-30293?
WebKitGTK versions up to and including 2.36.0 and WPE WebKit are affected by CVE-2022-30293.
How can I fix CVE-2022-30293?
To fix CVE-2022-30293, upgrade to the latest versions of WebKitGTK or WPE WebKit as provided by the respective vendors.
Where can I find more information about CVE-2022-30293?
You can find more information about CVE-2022-30293 at the links: [http://www.openwall.com/lists/oss-security/2022/05/30/1](http://www.openwall.com/lists/oss-security/2022/05/30/1), [https://bugs.webkit.org/show_bug.cgi?id=237187](https://bugs.webkit.org/show_bug.cgi?id=237187), [https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0](https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0).