Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 930380 (CVE-2024-3853, CVE-2024-3855, CVE-2024-3856, CVE-2024-3858, CVE-2024-3860, CVE-2024-3862, CVE-2024-3865) - <www-client/firefox{-bin,}-{125.0.1,115.10.0}: multiple vulnerabilities
Summary: <www-client/firefox{-bin,}-{125.0.1,115.10.0}: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2024-3853, CVE-2024-3855, CVE-2024-3856, CVE-2024-3858, CVE-2024-3860, CVE-2024-3862, CVE-2024-3865
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [stable?]
Keywords:
Depends on:
Blocks: CVE-2024-2609, CVE-2024-3302, CVE-2024-3854, CVE-2024-3857, CVE-2024-3859, CVE-2024-3861, CVE-2024-3864, MSFA2024-18, MSFA2024-19, MSFA2024-20
  Show dependency tree
 
Reported: 2024-04-21 17:54 UTC by Christopher Fore
Modified: 2024-04-21 17:55 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Fore 2024-04-21 17:54:08 UTC
The following only effect rapid (125.0):

CVE-2024-3853:

A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started.


CVE-2024-3855:

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads.


CVE-2024-3856:

A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array.


CVE-2024-3858:

It was possible to mutate a JavaScript object so that the JIT could crash while tracing it.


CVE-2024-3860:

An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash.


CVE-2024-3862:

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment.


CVE-2024-3865:

Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.



See tracker for <115.10 vulnerabilities, as they affect all products.