CVE-2021-43535: Use After Free
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash.
Other sources
A use-after-free could have occurred when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-43535?
CVE-2021-43535 is a vulnerability that could lead to memory corruption and a potentially exploitable crash in Firefox, Thunderbird, and Firefox ESR.
Which software is affected by CVE-2021-43535?
Firefox versions earlier than 93, Thunderbird versions earlier than 91.3, and Firefox ESR versions earlier than 91.3 are affected by CVE-2021-43535.
What is the severity of CVE-2021-43535?
The severity of CVE-2021-43535 is high with a severity value of 7.
How can I fix CVE-2021-43535 in Firefox?
To fix CVE-2021-43535 in Firefox, update your browser to version 93 or later.
How can I fix CVE-2021-43535 in Thunderbird or Firefox ESR?
To fix CVE-2021-43535 in Thunderbird or Firefox ESR, update your software to version 91.3 or later.