Alpine: webkit2gtk: security update to 2.34.4-r0

high Tenable Self-Hosted Container Security Plugin ID 426690

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2,
macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted
web content may lead to arbitrary code execution. (CVE-2021-30954)

- A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2,
macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted
web content may lead to arbitrary code execution. (CVE-2021-30934)

- A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.2,
macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted
web content may lead to arbitrary code execution. (CVE-2021-30936, CVE-2021-30951)

- An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS
Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web
content may lead to arbitrary code execution. (CVE-2021-30952)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-30934

https://security.alpinelinux.org/vuln/CVE-2021-30936

https://security.alpinelinux.org/vuln/CVE-2021-30951

https://security.alpinelinux.org/vuln/CVE-2021-30952

https://security.alpinelinux.org/vuln/CVE-2021-30953

https://security.alpinelinux.org/vuln/CVE-2021-30954

https://security.alpinelinux.org/vuln/CVE-2021-30984

https://security.alpinelinux.org/vuln/CVE-2022-22594

https://security.alpinelinux.org/vuln/CVE-2022-22637

Plugin Details

Severity: High

ID: 426690

Version: Revision 1.4

Type: Local

Published: 5/16/2025

Updated: 3/16/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 8.9

Percentile: 99.71

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2021-30954

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS Score Source: CVE-2022-22637

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 8/24/2021

Reference Information

CVE: CVE-2021-30934, CVE-2021-30936, CVE-2021-30951, CVE-2021-30952, CVE-2021-30953, CVE-2021-30954, CVE-2021-30984, CVE-2022-22594, CVE-2022-22637