CVE-2022-22740: Use After Free
Published Jan 11, 2022
·Updated
Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially exploitable crash.
Affected Software
6 affected componentsFixes available
Mozilla Thunderbird<91.5
91.5
Mozilla Firefox<96.0
Mozilla Firefox ESR<91.5
Mozilla Thunderbird<91.5
Mozilla Firefox<96
96
Mozilla Firefox ESR<91.5
91.5
Event History
Jan 11, 2022
CVE Published
via Mozilla·12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-22740?
CVE-2022-22740 has been assessed with a moderate severity rating.
2
How do I fix CVE-2022-22740?
To mitigate CVE-2022-22740, update Mozilla Firefox to version 96 or later, or Firefox ESR to version 91.5 or later.
3
Which versions are affected by CVE-2022-22740?
CVE-2022-22740 affects Firefox versions up to 96, Firefox ESR versions up to 91.5, and Thunderbird versions up to 91.5.
4
What type of vulnerability is CVE-2022-22740?
CVE-2022-22740 is a use-after-free vulnerability that can cause crashes.
5
What products are impacted by CVE-2022-22740?
CVE-2022-22740 impacts Mozilla Firefox, Mozilla Firefox ESR, and Mozilla Thunderbird.