CVE-2021-38504: Use After Free
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-38504?
The severity of CVE-2021-38504 is high with a CVSS score of 8.8.
Which software is affected by CVE-2021-38504?
CVE-2021-38504 affects Firefox versions less than 94, Thunderbird versions less than 91.3, and Firefox ESR versions less than 91.3.
How can I fix CVE-2021-38504?
To fix CVE-2021-38504, update to Firefox version 94 or later, Thunderbird version 91.3 or later, or Firefox ESR version 91.3 or later.
What is the description of CVE-2021-38504?
CVE-2021-38504 is a vulnerability that could lead to memory corruption and a potentially exploitable crash when interacting with an HTML input element's file picker dialog with webkitdirectory set.
Where can I find more information about CVE-2021-38504?
You can find more information about CVE-2021-38504 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1730156), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2021/12/msg00030.html).