Your submission was sent successfully! Close

CVE-2021-43535

Published: 8 December 2021

A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.

Priority

Medium

CVSS 3 base score: 8.8

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(94.0+build3-0ubuntu0.18.04.1)
focal Not vulnerable
(94.0+build3-0ubuntu0.20.04.1)
hirsute Not vulnerable
(94.0+build3-0ubuntu0.21.04.1)
impish Not vulnerable
(94.0+build3-0ubuntu0.21.10.1)
jammy Not vulnerable
(94.0+build3-0ubuntu1)
trusty Does not exist

upstream Needs triage

xenial Needed

thunderbird
Launchpad, Ubuntu, Debian
bionic
Released (1:91.5.0+build1-0ubuntu0.18.04.1)
focal
Released (1:91.5.0+build1-0ubuntu0.20.04.1)
hirsute Ignored
(reached end-of-life)
impish Not vulnerable
(1:91.3.1+build1-0ubuntu0.21.10.1)
jammy Not vulnerable
(1:91.3.1+build1-0ubuntu1)
trusty Does not exist

upstream Needs triage

xenial Needed