CVE-2020-6820: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
Last updated 25 August 2025
Other sources
Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts.
— CISA
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 74.0.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 68.6.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 68.7 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0.6-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.13.0esr-1~deb11u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.13.0esr-1~deb12u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.13.0esr-1~deb13u1Fixed in 140.12.0esr-1Fixed in 140.13.0esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 74.0.1 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 68.6.1 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 68.7.0 - Compensating control
Given targeted attacks in the wild, restrict exposure to untrusted content until all affected Firefox/Thunderbird versions are upgraded.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6820?
CVE-2020-6820 is a use-after-free vulnerability in Mozilla Firefox and Thunderbird.
Which software is affected by CVE-2020-6820?
Mozilla Firefox < 74.0.1, Firefox ESR < 68.6.1, and Thunderbird < 68.7.0 are affected.
How severe is CVE-2020-6820?
CVE-2020-6820 has a severity rating of 8.1 (critical).
How do I fix CVE-2020-6820 in Mozilla Firefox?
Update Mozilla Firefox to version 74.0.1 or higher to fix CVE-2020-6820.
How do I fix CVE-2020-6820 in Thunderbird?
Upgrade Thunderbird to version 68.7.0 or higher to fix CVE-2020-6820.