CVE-2026-78376

8.8

Red Hat · Enterprise Linux

A use after free vulnerability in WebKitGTK allows remote attackers to trigger memory corruption and potentially execute arbitrary code via a crafted web page.

Executive summary

A critical use after free vulnerability in WebKitGTK within Red Hat Enterprise Linux versions 6 through 9 poses a significant risk of remote code execution.

Vulnerability

The flaw is a use after free condition (CWE-416) within the WebKitGTK engine, which can be triggered by an unauthenticated attacker through user interaction, such as convincing a victim to visit a malicious website.

Business impact

Successful exploitation allows an attacker to achieve code execution with the privileges of the user running the affected application. Given the CVSS score of 8.8, the potential for total system impact is high, which could lead to complete data compromise or unauthorized control over the affected workstation or server.

Remediation

Immediate Action: Review the official Red Hat security advisory for available package updates and apply the necessary patches to your RHEL distributions immediately.

Proactive Monitoring: Monitor system logs for unusual crashes or unexpected process terminations associated with web-based applications.

Compensating Controls: Ensure that web browsers are kept up to date and consider using browser-based security extensions or sandboxing technologies to limit the impact of potential exploits.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates immediate attention. Organizations should prioritize updating all RHEL systems that utilize WebKitGTK to ensure they are patched against this memory corruption flaw, thereby mitigating the risk of remote exploitation.

More Red Hat CVEs