CVE-2024-6609: Memory corruption in NSS
Last updated 2 September 2024
Other sources
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.2-2 - Upgrade
Upgrade
debian/nssto a version that resolves this vulnerability.Fixed in 2:3.105-2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 128
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6609?
CVE-2024-6609 is classified as a moderate severity vulnerability affecting Mozilla Firefox and Thunderbird.
How do I fix CVE-2024-6609?
To fix CVE-2024-6609, users should upgrade to Firefox and Thunderbird version 128.0 or later.
Which versions of Firefox are affected by CVE-2024-6609?
CVE-2024-6609 affects Firefox versions prior to 128.0.
Which versions of Thunderbird are affected by CVE-2024-6609?
CVE-2024-6609 affects Thunderbird versions prior to 128.0.
What type of issue does CVE-2024-6609 represent?
CVE-2024-6609 is an issue related to memory management in elliptic curve key handling.