CVE-2023-3600: Use-after-free in workers
During the worker lifecycle, a use-after-free condition could have occured, which could have led to a potentially exploitable crash.
Other sources
During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 115.0.2 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 115.0.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.0.1 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 138.0.1-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:128.10.0esr-1~deb11u1Fixed in 1:128.8.0esr-1~deb12u1Fixed in 1:128.10.0esr-1~deb12u1Fixed in 1:128.9.0esr-1Fixed in 1:128.10.0esr-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.0.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.0.1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 115.0.2 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.0.2 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 115.0.1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3600.
What is the severity of CVE-2023-3600?
The severity of CVE-2023-3600 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2023-3600?
CVE-2023-3600 affects Firefox versions less than 115.0.2, Firefox ESR versions less than 115.0.2, and Thunderbird versions less than 115.0.1.
How can the use-after-free condition be exploited?
The use-after-free condition could potentially lead to a crash that can be exploited.
How can I fix CVE-2023-3600?
To fix CVE-2023-3600, update to Firefox 115.0.2, Firefox ESR 115.0.2, or Thunderbird 115.0.1 or later.