CVE-2022-45405: Use After Free
Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Other sources
Freeing arbitrary nsIInputStream's on a different thread than creation could have led to a use-after-free and potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-45405?
CVE-2022-45405 is a vulnerability that allows freeing arbitrary nsIInputStream's on a different thread than creation, leading to a use-after-free and potentially exploitable crash.
Which software is affected by CVE-2022-45405?
CVE-2022-45405 affects Firefox ESR versions before 102.5, Thunderbird versions before 102.5, and Firefox versions before 107.
What is the severity of CVE-2022-45405?
The severity of CVE-2022-45405 is high with a CVSS score of 6.5.
How can CVE-2022-45405 be exploited?
CVE-2022-45405 can be exploited by freeing arbitrary nsIInputStream's on a different thread than creation, causing a use-after-free vulnerability.
How can I fix CVE-2022-45405?
To fix CVE-2022-45405, update Firefox ESR to version 102.5 or later, Thunderbird to version 102.5 or later, or Firefox to version 107 or later.