CVE-2024-4764: Use After Free
Last updated 24 July 2024
Other sources
Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 130.0.1-1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 126 - Upgrade
Upgrade
firefoxto a version that resolves this vulnerability.Fixed in 126
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4764?
CVE-2024-4764 is classified as a critical vulnerability that can lead to use-after-free conditions in multiple WebRTC threads.
How do I fix CVE-2024-4764?
To fix CVE-2024-4764, upgrade Firefox to version 126 or later.
What versions of Firefox are affected by CVE-2024-4764?
CVE-2024-4764 affects all versions of Firefox below 126.
Is CVE-2024-4764 exploitable remotely?
Yes, CVE-2024-4764 can potentially be exploited remotely, affecting users via malicious web content.
What underlying feature does CVE-2024-4764 affect?
CVE-2024-4764 affects audio input handling in the WebRTC functionality of Firefox.