First published: Tue Mar 04 2025(Updated: )
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <136 | |
Firefox ESR | <128.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2349790 is considered to be critical due to its potential to allow execution of arbitrary JavaScript.
To fix REDHAT-BUG-2349790, update Firefox to version 136 or newer, or Firefox ESR to version 128.8 or newer.
REDHAT-BUG-2349790 affects Firefox versions earlier than 136 and Firefox ESR versions earlier than 128.8.
REDHAT-BUG-2349790 can be exploited to interrupt RegExp processing, allowing attackers to run additional JavaScript unexpectedly.
REDHAT-BUG-2349790 affects users of Mozilla Firefox and Firefox ESR running vulnerable versions.