CVE-2022-40960: Use After Free
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-40960?
CVE-2022-40960 is a vulnerability in Firefox ESR, Thunderbird, and Firefox that allows concurrent use of the URL parser with non-UTF-8 data, leading to a use-after-free and potentially exploitable crash.
Which software versions are affected by CVE-2022-40960?
Firefox ESR versions below 102.3, Thunderbird versions below 102.3, and Firefox versions below 105 are affected by CVE-2022-40960.
How severe is CVE-2022-40960?
CVE-2022-40960 has a severity value of 6.5, which is considered high.
How can I fix CVE-2022-40960?
To fix CVE-2022-40960, update to Firefox ESR version 102.3 or later, Thunderbird version 102.3 or later, or Firefox version 105 or later.
Where can I find more information about CVE-2022-40960?
You can find more information about CVE-2022-40960 in the following references: - [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1787633) - [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2022-42/) - [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2022-40/)