A flaw was found in WebKitGTK. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: A use after free issue in the AudioSourceProviderGStreamer class was addressed with improved memory management. Reference: https://webkitgtk.org/security/WSA-2021-0001.html
Created webkit2gtk3 tracking bugs for this issue: Affects: fedora-all [bug 1928887]
External References: https://webkitgtk.org/security/WSA-2021-0001.html
Upstream fix: https://trac.webkit.org/changeset/270184/webkit [trunk] https://trac.webkit.org/changeset/272646/webkit [trunk] https://trac.webkit.org/changeset/272713/webkit [2.30] https://trac.webkit.org/changeset/272714/webkit [2.30]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4381 https://access.redhat.com/errata/RHSA-2021:4381
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-13558