REDHAT-BUG-2382717: Null Pointer Dereference
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2382717?
The severity of REDHAT-BUG-2382717 is considered critical due to the potential for a null pointer dereference.
How do I fix REDHAT-BUG-2382717?
To fix REDHAT-BUG-2382717, update to the latest version of Firefox, Firefox ESR, or Thunderbird that is not affected.
What software is affected by REDHAT-BUG-2382717?
REDHAT-BUG-2382717 impacts Firefox versions below 141, several Firefox ESR versions, and Thunderbird versions below 141.
What happens if REDHAT-BUG-2382717 is exploited?
Exploitation of REDHAT-BUG-2382717 could lead to application crashes due to null pointer dereferences in the JavaScript engine.
Is there a workaround for REDHAT-BUG-2382717?
There are no official workarounds for REDHAT-BUG-2382717, so it is recommended to apply the necessary updates.