First published: Tue Mar 23 2021(Updated: )
A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.)
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <87 | 87 |
Firefox | <87.0 | |
Firefox ESR | <78.9 | |
Firefox ESR | <78.9 | 78.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2021-29955 is rated as a high-severity vulnerability due to its potential for leaking arbitrary memory addresses.
To mitigate CVE-2021-29955, update to Mozilla Firefox version 87 or later or apply the relevant security patches provided by Mozilla.
CVE-2021-29955 affects Mozilla Firefox versions prior to 87 and Firefox ESR versions before 78.9.
CVE-2021-29955 may enable attackers to conduct JIT type confusion attacks due to memory leakage.
There are no specific workarounds for CVE-2021-29955, the best course of action is to update to the latest version of the affected software.