When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-firefoxalma-upgrade-thunderbird | May 4, 2022 | Apr 11, 2022 | |
| Alpine Linux | alpine-linux-upgrade-firefox-esralpine-linux-upgrade-firefoxalpine-linux-upgrade-thunderbirdalpine-linux-upgrade-librewolf | Aug 22, 2024 | Dec 22, 2022 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-thunderbirdamazon-linux-ami-2-upgrade-thunderbird-debuginfo | Jul 4, 2022 | Jul 4, 2022 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Dec 22, 2022 | |
| Centos_linux | — | centos-upgrade-firefoxcentos-upgrade-firefox-debuginfocentos-upgrade-firefox-debugsourcecentos-upgrade-thunderbirdcentos-upgrade-thunderbird-debuginfocentos-upgrade-thunderbird-debugsource | Apr 11, 2022 | Apr 8, 2022 |
| Debian | debian-upgrade-firefox-esrdebian-upgrade-thunderbird | Apr 8, 2022 | Apr 8, 2022 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-client-thunderbirdgentoo-linux-upgrade-mail-client-thunderbird-bingentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bin | Aug 11, 2022 | Aug 10, 2022 | |
| Mfsa2022 13 | mozilla-firefox-upgrade-99_0 | Apr 6, 2022 | Apr 5, 2022 | |
| Mfsa2022 14 | mozilla-firefox-esr-upgrade-91_8 | Apr 6, 2022 | Apr 5, 2022 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-91_8 | Apr 7, 2022 | Apr 5, 2022 | |
| Oracle_linux | — | oracle-linux-upgrade-firefoxoracle-linux-upgrade-thunderbird | Apr 9, 2022 | Apr 5, 2022 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-firefoxredhat-upgrade-firefox-debuginforedhat-upgrade-firefox-debugsourceredhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | Apr 11, 2022 | Apr 8, 2022 | |
| Rocky_linux | rocky-upgrade-firefoxrocky-upgrade-firefox-debuginforocky-upgrade-firefox-debugsourcerocky-upgrade-thunderbirdrocky-upgrade-thunderbird-debuginforocky-upgrade-thunderbird-debugsource | Mar 5, 2024 | Dec 22, 2022 | |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Oct 26, 2022 | Apr 7, 2022 |
| Ubuntu | ubuntu-upgrade-firefoxubuntu-upgrade-libmozjs-91-0ubuntu-upgrade-thunderbird | Apr 8, 2022 | Apr 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub