CVE-2020-6819: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
Last updated 25 August 2025
Other sources
Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.
— CISA
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 74.0.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 68.6.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 68.7 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0.6-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.13.0esr-1~deb11u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.13.0esr-1~deb12u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.13.0esr-1~deb13u1Fixed in 140.12.0esr-1Fixed in 140.13.0esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 74.0.1 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 68.6.1 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 68.7.0 - Compensating control
Given targeted attacks in the wild abusing this flaw, restrict exposure of affected browsers (Firefox/Firefox ESR/Thunderbird) while updating (e.g., limit access in enterprise environments or isolate endpoints) until the fixed versions are deployed.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6819?
CVE-2020-6819 is a use-after-free vulnerability in Mozilla Firefox and Thunderbird.
Which software is affected by CVE-2020-6819?
Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1 are affected by CVE-2020-6819.
What is the severity of CVE-2020-6819?
CVE-2020-6819 has a severity rating of 8.1 (critical).
Are there any known attacks exploiting CVE-2020-6819?
Yes, there are targeted attacks in the wild abusing this vulnerability.
How can I fix CVE-2020-6819?
Update Thunderbird to version >= 68.7.0, Firefox to version >= 74.0.1, or Firefox ESR to version >= 68.6.1 to fix CVE-2020-6819.