CVE-2023-4577: Memory corruption in JIT UpdateRegExpStatics
Last updated 24 July 2024
Other sources
When UpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-36/#CVE-2023-4577
— Red Hat
When UpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
— Launchpad
When UpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-4577?
The severity of CVE-2023-4577 is high.
Which software is affected by CVE-2023-4577?
Mozilla Firefox versions up to exclusive 117, Mozilla Firefox ESR versions up to exclusive 115.2, and Mozilla Thunderbird versions up to exclusive 115.2 are affected by CVE-2023-4577.
How can I fix CVE-2023-4577?
To fix CVE-2023-4577, update to a version of Mozilla Firefox or Mozilla Thunderbird that is equal to or higher than 117, update to Mozilla Firefox ESR version 115.2 or higher, or apply the necessary security patch for your operating system and package manager.
Where can I find more information about CVE-2023-4577?
You can find more information about CVE-2023-4577 on the official CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4577), the Ubuntu Security Notices (https://ubuntu.com/security/notices/USN-6320-1), and the NIST National Vulnerability Database (https://nvd.nist.gov/vuln/detail/CVE-2023-4577).