CVE-2025-13502

Discovered by AISLEPUBLISHEDCWE-125

Description

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

CVSS Base Scores

CVSS v3.1(Primary)
7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionStatus
The WebKitGTK TeamWebKitGTK0affected
The WebKitGTK TeamWebKitGTK0:2.50.3-2.el7_9unaffected
The WebKitGTK TeamWebKitGTK0:2.50.3-1.el8_10
The WebKitGTK TeamWebKitGTK0:2.50.3-2.el8_2
The WebKitGTK TeamWebKitGTK0:2.50.3-2.el8_4
The WebKitGTK TeamWebKitGTK0:2.50.3-2.el8_6
The WebKitGTK TeamWebKitGTK0:2.50.3-2.el8_8
The WebKitGTK TeamWebKitGTK0:2.50.3-1.el9_7
The WebKitGTK TeamWebKitGTK0:2.50.3-1.el9_0
The WebKitGTK TeamWebKitGTK0:2.50.3-1.el9_2
The WebKitGTK TeamWebKitGTK0:2.50.3-1.el9_4
The WebKitGTK TeamWebKitGTK0:2.50.3-1.el9_6
Red HatWebKitGTK0affected
Red HatWebKitGTK0:2.50.3-2.el7_9unaffected
Red HatWebKitGTK0:2.50.3-1.el8_10
Red HatWebKitGTK0:2.50.3-2.el8_2
Red HatWebKitGTK0:2.50.3-2.el8_4
Red HatWebKitGTK0:2.50.3-2.el8_6
Red HatWebKitGTK0:2.50.3-2.el8_8
Red HatWebKitGTK0:2.50.3-1.el9_7
Red HatWebKitGTK0:2.50.3-1.el9_0
Red HatWebKitGTK0:2.50.3-1.el9_2
Red HatWebKitGTK0:2.50.3-1.el9_4
Red HatWebKitGTK0:2.50.3-1.el9_6

Credits

  • Red Hat would like to thank Aisle Research and Stanislav Fort for reporting this issue.

References