CVE-2019-8375: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 15.7% chance of exploitation in the next 30 days.
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 18.10 only
- Opensuse Leap: version 15.0 only; version 42.3 only
- WebKitGTK WebKitGTK: up to and including 2.23.90
- WebKitGTK Webkitgtk+: up to and including 2.22.6
Published 2019-02-24. Last modified 2026-06-17.