PT-2022-1783 · Mozilla+10 · Firefox Esr+14

Du Sihang

+4

·

Published

2022-03-05

·

Updated

2024-06-15

·

CVE-2022-26486

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 97.0.2 Mozilla Firefox ESR versions prior to 91.6.1 Mozilla Firefox for Android versions prior to 97.3.0 Thunderbird versions prior to 91.6.2 Focus versions prior to 97.3.0
Description The issue is related to a use-after-free vulnerability in the WebGPU interface, which can be exploited by a remote attacker to execute arbitrary code. There have been reports of attacks in the wild abusing this flaw. The vulnerability is associated with the WebGPU IPC framework, where an unexpected message could lead to a use-after-free and exploitable sandbox escape.
Recommendations For Mozilla Firefox versions prior to 97.0.2, update to version 97.0.2 or later. For Mozilla Firefox ESR versions prior to 91.6.1, update to version 91.6.1 or later. For Mozilla Firefox for Android versions prior to 97.3.0, update to version 97.3.0 or later. For Thunderbird versions prior to 91.6.2, update to version 91.6.2 or later. For Focus versions prior to 97.3.0, update to version 97.3.0 or later. As a temporary workaround, consider disabling the WebGPU interface until a patch is available. Restrict access to the WebGPU IPC framework to minimize the risk of exploitation.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:0818
ALSA-2022:0845
ALT-PU-2022-1443
ALT-PU-2022-1445
ALT-PU-2022-1447
ALT-PU-2022-1469
ALT-PU-2022-1479
ALT-PU-2022-1502
ALT-PU-2022-1519
ALT-PU-2022-1781
ALT-PU-2022-2053
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-01147
CESA-2022_0818
CESA-2022_0824
CESA-2022_0845
CESA-2022_0850
CVE-2022-26486
DLA-2933-1
DLA-2939-1
DSA-5090-1
DSA-5094-1
ELSA-2022-0818
ELSA-2022-0824
ELSA-2022-0845
ELSA-2022-0850
MGASA-2022-0089
MGASA-2022-0094
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2022:0783-1
OPENSUSE-SU-2022:0804-1
OPENSUSE-SU-2022_0783-1
OPENSUSE-SU-2022_0804-1
OPENSUSE-SU-2024:11909-1
RHSA-2022:0815
RHSA-2022:0816
RHSA-2022:0817
RHSA-2022:0818
RHSA-2022:0824
RHSA-2022:0843
RHSA-2022:0845
RHSA-2022:0847
RHSA-2022:0850
RHSA-2022:0853
RHSA-2022_0818
RHSA-2022_0824
RHSA-2022_0845
RHSA-2022_0850
RLSA-2022:0818
RLSA-2022:0845
RLSA-2022_0818
RLSA-2022_0845
SUSE-SU-2022:0777-1
SUSE-SU-2022:0778-1
SUSE-SU-2022:0783-1
SUSE-SU-2022:0804-1
SUSE-SU-2022:14906-1
SUSE-SU-2022_14906-1
USN-5314-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Focus
Linuxmint
Firefox
Firefox Esr
Firefox For Android
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu