CVE-2021-38498: Use After Free
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-38498?
CVE-2021-38498 is a vulnerability in Mozilla Thunderbird and Firefox that can cause a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash.
How severe is CVE-2021-38498?
CVE-2021-38498 has a severity rating of medium.
Which software versions are affected by CVE-2021-38498?
CVE-2021-38498 affects Mozilla Thunderbird up to version 91.2, Firefox ESR up to version 91.2, and Firefox up to version 93.
How can I fix CVE-2021-38498?
To fix CVE-2021-38498, update Mozilla Thunderbird to version 91.2, Firefox ESR to version 91.2, or Firefox to version 93.
Where can I find more information about CVE-2021-38498?
You can find more information about CVE-2021-38498 in the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1729642), [Mozilla Security Advisory MFSAs](https://www.mozilla.org/en-US/security/advisories/mfsa2021-47/), [Mozilla Security Advisory MFSA2021-43](https://www.mozilla.org/en-US/security/advisories/mfsa2021-43/).