First published: Tue Jan 11 2022(Updated: )
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.5 | 91.5 |
<96 | 96 | |
<91.5 | 91.5 | |
<91.5 | 91.5 | |
Mozilla Firefox | <96.0 | |
Mozilla Firefox ESR | <91.5 | |
Mozilla Thunderbird | <91.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-22737 is classified as potentially exploitable due to a race condition that can lead to a use-after-free situation.
To fix CVE-2022-22737, upgrade to Mozilla Firefox ESR version 91.5, Firefox version 96, or Thunderbird version 91.5.
CVE-2022-22737 affects Mozilla Firefox ESR versions prior to 91.5, Firefox versions prior to 96, and Thunderbird versions prior to 91.5.
CVE-2022-22737 is a use-after-free vulnerability triggered by race conditions when handling audio sinks.
Yes, CVE-2022-22737 can lead to crashes due to the use-after-free condition that may be triggered during audio playback.