Impact
This vulnerability is a race condition (CWE‑362) combined with a use‑after‑free (CWE‑416) in the graphics subsystem of Mozilla applications. The flaw revolves around shared graphics resources being freed while still in use, which can lead to memory corruption, program crashes, or other undesirable behavior. This type of defect may allow an attacker to corrupt data structures or cause a denial‑of‑service to a process rendering untrusted graphics.
Affected Systems
Affected products include Mozilla Firefox and Mozilla Thunderbird. Versions prior to Firefox 154, and the ESR releases 115.39, 140.14, and 153.1, contain the vulnerable graphics code. Likewise, Thunderbird versions older than 154, as well as the ESR builds 140.14 and 153.1, are impacted. All other recent releases have the fix applied.
Risk and Exploitability
The CVSS score of 4.2 classifies this flaw as low‑to‑moderate severity. The EPSS score is reported as < 1 %, indicating a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further supporting its limited risk profile. The likely attack vector involves the delivery of malicious graphics content – such as a specially crafted webpage or document – that triggers the race condition during rendering. If such content is processed on an affected system, an attacker could potentially crash the application or corrupt memory, but remote code execution is not directly supported by the available description.
OpenCVE Enrichment
Debian DLA
Debian DSA