CVE-2021-29986

CVSS v3.1 8.1 (High)
81% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 1.69 % (88th)
1.69% Progress
Affected Products 4
Advisories 39

A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. Note: This issue only affected Linux operating systems. Other operating systems are unaffected. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2021-08-17 20:15:07
(3 years ago)
Updated Date
2022-12-09 19:17:08
(21 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 91.0 version cpe:2.3:a:mozilla:firefox < 91.0
OR  
  Running on/with
  Mozilla Firefox Esr prior 78.13.0 version cpe:2.3:a:mozilla:firefox_esr < 78.13.0
OR  
  Running on/with
  Mozilla Thunderbird prior 78.13.0 version cpe:2.3:a:mozilla:thunderbird < 78.13.0
OR  
  Running on/with
  Linux Kernel cpe:2.3:o:linux:linux_kernel:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...