VDB

DEBIAN-CVE-2020-13753

DEBIAN-CVE-2020-13753 PUBLISHED CVSS 10 CRITICAL

The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal's input buffer, similar to CVE-2017-5226.

Risk Scores

CVSS v3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11wpewebkit0, 0, 0
Debian:14webkit2gtk0, 0, 0
Debian:13webkit2gtk0, 0, 0
Debian:12webkit2gtk0, 0, 0
Debian:12wpewebkit0, 0, 0
Debian:13wpewebkit0, 0, 0
Debian:11webkit2gtk0, 0, 0
Debian:14wpewebkit0, 0, 0

Timeline

  • Jul 14, 2020 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›