First published: Tue Mar 04 2025(Updated: )
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, and Firefox ESR < 128.8.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <136 | |
Firefox ESR | <115.21<128.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2349786 has the potential to lead to a crash in affected versions of Firefox and Firefox ESR, indicating a high severity due to the risk of a use-after-free vulnerability.
To fix REDHAT-BUG-2349786, update your Firefox or Firefox ESR to the latest version beyond 136 for Firefox and beyond 115.21 or 128.8 for Firefox ESR.
REDHAT-BUG-2349786 affects Firefox versions below 136 and Firefox ESR versions below 115.21 and below 128.8.
Yes, REDHAT-BUG-2349786 can potentially be exploited remotely through WebTransport connections in the affected versions.
Currently, the best mitigation for REDHAT-BUG-2349786 is to upgrade to the patched versions as there are no official workarounds available.