Mozilla · Firefox Esr · CVE-2021-29986
**Name of the Vulnerable Software and Affected Versions**
Thunderbird versions prior to 78.13
Thunderbird versions prior to 91
Firefox ESR versions prior to 78.13
Firefox versions prior to 91
**Description**
A suspected race condition when calling `getaddrinfo` led to memory corruption and a potentially exploitable crash. This issue only affects Linux operating systems, with other operating systems being unaffected. The vulnerability can be exploited by a remote attacker, who can create a special web page that, when opened by the victim, can cause memory corruption.
**Recommendations**
For Thunderbird versions prior to 78.13, update to version 78.13 or later.
For Thunderbird versions prior to 91, update to version 91 or later.
For Firefox ESR versions prior to 78.13, update to version 78.13 or later.
For Firefox versions prior to 91, update to version 91 or later.