CVE-2022-26485: Mozilla Firefox Use-After-Free Vulnerability
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes this flaw as: Removing an XSLT parameter during processing could have led to an exploitable use-after-free issue. There were reports of attacks in the wild abusing this flaw.
Other sources
As per Mozilla Security Advisory: Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw.
Reporter: Wang Gang, Liu Jialei, Du Sihang, Huang Yi & Yang Kang of 360 ATA Name: the Mozilla project
Advisory: https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/#CVE-2022-26485
— Red Hat
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
— CISA
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el7_9 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el7_9 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_5 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_5 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_1 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_2 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_2 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_4 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_4 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 97.0.2 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 91.6.1 - Upgrade
Upgrade
Mozilla Focusto a version that resolves this vulnerability.Fixed in 97.3 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 91.6.2 - Upgrade
Upgrade
redhat/Firefoxto a version that resolves this vulnerability.Fixed in 97.0.2 - Upgrade
Upgrade
redhat/Firefox ESRto a version that resolves this vulnerability.Fixed in 91.6.1 - Upgrade
Upgrade
redhat/Thunderbirdto a version that resolves this vulnerability.Fixed in 91.6.2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-26485?
CVE-2022-26485 is a use-after-free vulnerability affecting Mozilla Firefox, Firefox ESR, Firefox for Android, Thunderbird, and Focus.
How severe is CVE-2022-26485?
CVE-2022-26485 has a severity score of 8.8 (critical).
Which versions of Firefox are affected by CVE-2022-26485?
Firefox versions prior to 97.0.2 are affected by CVE-2022-26485.
How can I fix CVE-2022-26485?
To fix CVE-2022-26485, update Firefox to version 97.0.2 or later.
Are there any references for CVE-2022-26485?
Yes, you can find references for CVE-2022-26485 in the following links: [link1](https://www.cve.org/CVERecord?id=CVE-2022-26485), [link2](https://nvd.nist.gov/vuln/detail/CVE-2022-26485), [link3](https://bugzilla.redhat.com/show_bug.cgi?id=2061736), [link4](https://access.redhat.com/errata/RHSA-2022:0824).