In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
https://www.debian.org/security/2022/dsa-5155
https://www.debian.org/security/2022/dsa-5154
https://security.gentoo.org/glsa/202208-39
https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0