CVE-2021-38496: Use After Free
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-38496?
CVE-2021-38496 is a vulnerability that may result in memory corruption and a potentially exploitable crash in Thunderbird and Firefox.
Which software versions are affected by CVE-2021-38496?
CVE-2021-38496 affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
What is the severity of CVE-2021-38496?
CVE-2021-38496 has a severity rating of 8.8 (high).
How can I fix CVE-2021-38496?
To fix CVE-2021-38496, it is recommended to update Thunderbird and Firefox to the latest available versions.
Where can I find more information about CVE-2021-38496?
You can find more information about CVE-2021-38496 on the Mozilla Bugzilla and Mozilla Security Advisories websites, as well as the Debian LTS Announce mailing list.