When generating the assembly code for MLoadTypedArrayElementHole, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 99.0 (excluding) |
Firefox_esr | Mozilla | * | 91.8 (excluding) |
Thunderbird | Mozilla | * | 91.8 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | firefox-0:91.8.0-1.el7_9 | * |
Red Hat Enterprise Linux 7 | RedHat | thunderbird-0:91.8.0-1.el7_9 | * |
Red Hat Enterprise Linux 8 | RedHat | firefox-0:91.8.0-1.el8_5 | * |
Red Hat Enterprise Linux 8 | RedHat | thunderbird-0:91.8.0-1.el8_5 | * |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | RedHat | firefox-0:91.8.0-1.el8_1 | * |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | RedHat | thunderbird-0:91.8.0-1.el8_1 | * |
Red Hat Enterprise Linux 8.2 Extended Update Support | RedHat | firefox-0:91.8.0-1.el8_2 | * |
Red Hat Enterprise Linux 8.2 Extended Update Support | RedHat | thunderbird-0:91.8.0-1.el8_2 | * |
Red Hat Enterprise Linux 8.4 Extended Update Support | RedHat | firefox-0:91.8.0-1.el8_4 | * |
Red Hat Enterprise Linux 8.4 Extended Update Support | RedHat | thunderbird-0:91.8.0-1.el8_4 | * |
Firefox | Ubuntu | bionic | * |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | focal | * |
Firefox | Ubuntu | impish | * |
Firefox | Ubuntu | jammy | * |
Firefox | Ubuntu | kinetic | * |
Firefox | Ubuntu | lunar | * |
Firefox | Ubuntu | mantic | * |
Firefox | Ubuntu | noble | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | xenial | * |
Mozjs38 | Ubuntu | bionic | * |
Mozjs38 | Ubuntu | esm-apps/bionic | * |
Mozjs38 | Ubuntu | upstream | * |
Mozjs52 | Ubuntu | bionic | * |
Mozjs52 | Ubuntu | esm-apps/focal | * |
Mozjs52 | Ubuntu | esm-infra/bionic | * |
Mozjs52 | Ubuntu | focal | * |
Mozjs52 | Ubuntu | upstream | * |
Mozjs68 | Ubuntu | focal | * |
Mozjs68 | Ubuntu | upstream | * |
Mozjs78 | Ubuntu | esm-apps/jammy | * |
Mozjs78 | Ubuntu | impish | * |
Mozjs78 | Ubuntu | jammy | * |
Mozjs78 | Ubuntu | kinetic | * |
Mozjs78 | Ubuntu | lunar | * |
Mozjs78 | Ubuntu | upstream | * |
Mozjs91 | Ubuntu | jammy | * |
Mozjs91 | Ubuntu | upstream | * |
Thunderbird | Ubuntu | bionic | * |
Thunderbird | Ubuntu | focal | * |
Thunderbird | Ubuntu | impish | * |
Thunderbird | Ubuntu | trusty | * |
Thunderbird | Ubuntu | upstream | * |
Thunderbird | Ubuntu | xenial | * |