First published: Sat Mar 05 2022(Updated: )
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <0:91.7.0-3.el7_9 | 0:91.7.0-3.el7_9 |
redhat/thunderbird | <0:91.7.0-2.el7_9 | 0:91.7.0-2.el7_9 |
redhat/firefox | <0:91.7.0-3.el8_5 | 0:91.7.0-3.el8_5 |
redhat/thunderbird | <0:91.7.0-2.el8_5 | 0:91.7.0-2.el8_5 |
redhat/firefox | <0:91.7.0-3.el8_1 | 0:91.7.0-3.el8_1 |
redhat/thunderbird | <0:91.7.0-2.el8_1 | 0:91.7.0-2.el8_1 |
redhat/firefox | <0:91.7.0-3.el8_2 | 0:91.7.0-3.el8_2 |
redhat/thunderbird | <0:91.7.0-2.el8_2 | 0:91.7.0-2.el8_2 |
redhat/firefox | <0:91.7.0-3.el8_4 | 0:91.7.0-3.el8_4 |
redhat/thunderbird | <0:91.7.0-2.el8_4 | 0:91.7.0-2.el8_4 |
Mozilla Firefox | <97.0.2 | 97.0.2 |
Mozilla Firefox ESR | <91.6.1 | 91.6.1 |
All of | ||
Mozilla Firefox | =97.3 | |
Google Android | ||
Mozilla Focus | <97.3 | 97.3 |
Mozilla Thunderbird | <91.6.2 | 91.6.2 |
redhat/Firefox | <97.0.2 | 97.0.2 |
redhat/Firefox ESR | <91.6.1 | 91.6.1 |
redhat/Thunderbird | <91.6.2 | 91.6.2 |
Mozilla Firefox | <97.0.2 | |
Mozilla Firefox | <97.3.0 | |
Mozilla Firefox ESR | <91.6.1 | |
Mozilla Firefox Focus | <97.3.0 | |
Mozilla Thunderbird | <91.6.2 | |
Mozilla Firefox | ||
<97.0.2 | ||
<97.3.0 | ||
<91.6.1 | ||
<97.3.0 | ||
<91.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-26486 is a use-after-free vulnerability in Mozilla Firefox.
The CVE-2022-26486 vulnerability has a severity rating of 9.6 out of 10, which is considered critical.
The CVE-2022-26486 vulnerability affects Firefox versions prior to 97.0.2, Firefox ESR versions prior to 91.6.1, Firefox for Android versions prior to 97.3.0, Thunderbird versions prior to 91.6.2, and Mozilla Focus versions prior to 97.3.0.
To fix the CVE-2022-26486 vulnerability, you should update Mozilla Firefox to version 97.0.2 or later, Firefox ESR to version 91.6.1 or later, Firefox for Android to version 97.3.0 or later, Thunderbird to version 91.6.2 or later, and Mozilla Focus to version 97.3.0 or later.
More information about CVE-2022-26486 can be found in the Mozilla Bugzilla and Mozilla Security Advisories.