CVE-2020-26972: Use After Free
Published Dec 15, 2020
·Updated
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<84
84
Mozilla Firefox<84.0
Event History
Dec 15, 2020
CVE Published
12:00 AM
Jan 7, 2021
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2020-26972?
CVE-2020-26972 is rated as a high severity vulnerability due to its potential to cause crashes and exploitation.
2
How do I fix CVE-2020-26972?
To fix CVE-2020-26972, users should update Mozilla Firefox to version 84 or later.
3
Which versions of Firefox are affected by CVE-2020-26972?
CVE-2020-26972 affects Mozilla Firefox versions prior to 84.
4
What type of vulnerability is CVE-2020-26972?
CVE-2020-26972 is classified as a use-after-free vulnerability.
5
Can CVE-2020-26972 be exploited remotely?
Yes, CVE-2020-26972 could potentially be exploited remotely through specially crafted content.