CVE-2022-26486: Mozilla Firefox Use-After-Free Vulnerability
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw.
Other sources
An unexpected message in the WebGPU IPC framework could lead to an exploitable sandbox escape and a use-after-free issue. An attacker with enough privileges could exploit this flaw leading to a complete system compromise
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el7_9 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el7_9 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_5 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_5 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_1 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_2 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_2 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:91.7.0-3.el8_4 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 0:91.7.0-2.el8_4 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 97.0.2 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 91.6.1 - Upgrade
Upgrade
Mozilla Focusto a version that resolves this vulnerability.Fixed in 97.3 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 91.6.2 - Upgrade
Upgrade
redhat/Firefoxto a version that resolves this vulnerability.Fixed in 97.0.2 - Upgrade
Upgrade
redhat/Firefox ESRto a version that resolves this vulnerability.Fixed in 91.6.1 - Upgrade
Upgrade
redhat/Thunderbirdto a version that resolves this vulnerability.Fixed in 91.6.2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-26486?
CVE-2022-26486 is a use-after-free vulnerability in Mozilla Firefox.
How severe is the CVE-2022-26486 vulnerability?
The CVE-2022-26486 vulnerability has a severity rating of 9.6 out of 10, which is considered critical.
Which software versions are affected by CVE-2022-26486?
The CVE-2022-26486 vulnerability affects Firefox versions prior to 97.0.2, Firefox ESR versions prior to 91.6.1, Firefox for Android versions prior to 97.3.0, Thunderbird versions prior to 91.6.2, and Mozilla Focus versions prior to 97.3.0.
How can I fix the CVE-2022-26486 vulnerability?
To fix the CVE-2022-26486 vulnerability, you should update Mozilla Firefox to version 97.0.2 or later, Firefox ESR to version 91.6.1 or later, Firefox for Android to version 97.3.0 or later, Thunderbird to version 91.6.2 or later, and Mozilla Focus to version 97.3.0 or later.
Where can I find more information about CVE-2022-26486?
More information about CVE-2022-26486 can be found in the Mozilla Bugzilla and Mozilla Security Advisories.