CVE-2019-11693: Buffer Overflow
Last updated 25 August 2025
Other sources
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash.
Note: this issue only occurs on Linux. Other operating systems are unaffected.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-14/#CVE-2019-11693
— Red Hat
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. Note: this issue only occurs on Linux. Other operating systems are unaffected.. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
— Launchpad
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. Note: this issue only occurs on Linux. Other operating systems are unaffected.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 67 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.11.0esr-1~deb11u1Fixed in 140.10.2esr-1~deb12u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.10.2esr-1~deb13u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.11.0esr-1Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.10.1esr-1~deb12u1Fixed in 1:140.11.0esr-1~deb12u1Fixed in 1:140.10.1esr-1~deb13u1Fixed in 1:140.11.0esr-1~deb13u1Fixed in 1:140.11.0esr-1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9815
- CVE-2019-9816
- CVE-2019-9817
- CVE-2019-9818
- CVE-2019-9819
- CVE-2019-9820
- CVE-2019-11691
- CVE-2019-11692
- CVE-2019-11693
- CVE-2019-7317
- CVE-2019-9797
- CVE-2018-18511
- CVE-2019-11694
- CVE-2019-11698
- CVE-2019-5798
- CVE-2019-9800
- CVE-2019-9821
- CVE-2019-11695
- CVE-2019-11696
- CVE-2019-11697
- CVE-2019-11700
- CVE-2019-11699
- CVE-2019-11701
- CVE-2019-9814
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-11693.
What is the severity of the vulnerability?
The severity of the vulnerability is critical with a CVSS score of 9.8.
Which graphics drivers on Linux are affected by this vulnerability?
The specific graphics drivers on Linux that are affected by this vulnerability have not been specified.
Which operating systems are affected by this vulnerability?
This vulnerability only occurs on Linux. Other operating systems are unaffected.
How can I fix this vulnerability?
Update your Mozilla Firefox or Mozilla Thunderbird to version 67.0+ or apply the appropriate patch according to your Linux distribution.