PT-2020-16585 · Mozilla+3 · Firefox+3
Brian Carpenter
·
Published
2020-12-15
·
Updated
2024-12-12
·
CVE-2020-26972
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 84
Description
The issue arises from the lifecycle of IPC Actors, where managed actors can outlive their manager actors. In such cases, the managed actors must ensure they do not attempt to use a dead actor they have a reference to. However, a check for this was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash.
Recommendations
For versions prior to 84, update to version 84 or later to resolve the issue. As a temporary workaround, consider disabling WebGL until a patch is available. Restrict access to WebGL-related functionalities to minimize the risk of exploitation.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Linuxmint
Ubuntu