CVE-2022-45409: Use After Free
The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Other sources
The garbage collector could have been aborted in several states and zones and GCRuntime::finishCollection may not have been called, leading to a use-after-free and potentially exploitable crash
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-45409.
Which software versions are affected by this vulnerability?
This vulnerability affects Mozilla Thunderbird versions up to and excluding 102.5, Mozilla Firefox versions up to and excluding 107, and Mozilla Firefox ESR versions up to and excluding 102.5.
What is the severity rating of CVE-2022-45409?
CVE-2022-45409 has a severity rating of 8.8 (high).
What is the description of this vulnerability?
The garbage collector could have been aborted in several states and GCRuntime::finishCollection may not have been called, leading to a use-after-free and potentially exploitable crash.
How can I fix this vulnerability?
To fix this vulnerability, update Mozilla Thunderbird to version 102.5 or higher, update Mozilla Firefox to version 107 or higher, or update Mozilla Firefox ESR to version 102.5 or higher.