PT-2022-2261 · Mozilla+10 · Thunderbird+12

Kirin

·

Published

2022-04-05

·

Updated

2025-09-29

·

CVE-2022-28282

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 99 Firefox ESR versions prior to 91.8 Thunderbird versions prior to 91.8
Description The issue is related to an error in memory release when handling links with rel="localization". This could allow a remote attacker to execute arbitrary code by using a specially crafted web page, potentially triggering a use-after-free error by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash.
Recommendations For Firefox versions prior to 99, update to version 99 or later. For Firefox ESR versions prior to 91.8, update to version 91.8 or later. For Thunderbird versions prior to 91.8, update to version 91.8 or later. As a temporary workaround, consider avoiding links with rel="localization" until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1287
ALSA-2022:1301
ALSA-2025_16880
ALT-PU-2022-1642
ALT-PU-2022-1809
ALT-PU-2022-1847
ALT-PU-2022-1855
ALT-PU-2022-1941
ALT-PU-2022-1951
ALT-PU-2022-1983
ALT-PU-2022-2044
ALT-PU-2022-2053
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-02370
CESA-2022_1287
CESA-2022_1301
CVE-2022-28282
DLA-2971-1
DLA-2978-1
DSA-5113-1
DSA-5118-1
ELSA-2022-1284
ELSA-2022-1287
ELSA-2022-1301
ELSA-2022-1302
MGASA-2022-0156
MGASA-2022-0157
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2022:1127-1
OPENSUSE-SU-2022_1127-1
OPENSUSE-SU-2022_1176-1
OPENSUSE-SU-2024:11975-1
OPENSUSE-SU-2024:14572-1
RHSA-2022:1283
RHSA-2022:1284
RHSA-2022:1285
RHSA-2022:1286
RHSA-2022:1287
RHSA-2022:1301
RHSA-2022:1302
RHSA-2022:1303
RHSA-2022:1305
RHSA-2022:1326
RHSA-2022_1284
RHSA-2022_1287
RHSA-2022_1301
RHSA-2022_1302
RLSA-2022:1287
RLSA-2022:1301
RLSA-2022_1287
RLSA-2022_1301
SUSE-RU-2022:1114-1
SUSE-RU-2022:1125-1
SUSE-RU-2022:14935-1
SUSE-SU-2022:1127-1
SUSE-SU-2022:1176-1
USN-5370-1
USN-5393-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu