CVE-2024-3854
published 2024-04-16CVE-2024-3854: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.73%
51.6th percentile
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 125.0.1-1 (sid) | firefox 125.0.1-1 (sid) |
| debian | firefox-esr | < firefox 125.0.1-1 (sid) | firefox 125.0.1-1 (sid) |
| debian | thunderbird | < firefox 125.0.1-1 (sid) | firefox 125.0.1-1 (sid) |
| mozilla | firefox | < 115.10 | 115.10 |
| mozilla | firefox | < 125.0 | 125.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 125.0.3+build1-0ubuntu0.20.04.1 | 125.0.3+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= 0 < 125.0.2+build1-0ubuntu0.20.04.2 | 125.0.2+build1-0ubuntu0.20.04.2 |
| mozilla | firefox | >= unspecified < 125 | 125 |
| mozilla | firefox_esr | >= unspecified < 115.10 | 115.10 |
| mozilla | thunderbird | < 115.10 | 115.10 |
| mozilla | thunderbird | >= 0 < 1:115.10.1-1~deb11u1 | 1:115.10.1-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:115.10.1-1~deb12u1 | 1:115.10.1-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:115.10.1-1 | 1:115.10.1-1 |
| mozilla | thunderbird | >= 0 < 1:115.10.1-1 | 1:115.10.1-1 |
| mozilla | thunderbird | >= 0 < 1:115.10.1+build1-0ubuntu0.20.04.1 | 1:115.10.1+build1-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:115.10.1+build1-0ubuntu0.22.04.1 | 1:115.10.1+build1-0ubuntu0.22.04.1 |
| mozilla | thunderbird | >= unspecified < 115.10 | 115.10 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regressions
vendor_ubuntu·2024-05-02·CVSS 3.7
[LOW] Firefox regressions
Title: Firefox regressions
Summary: USN-6747-1 caused some minor regressions in Firefox.
USN-6747-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-3852,
CVE-2024-3864, CVE-2024-3865)
Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)
Gary Kwong discovered that Firefox did not properly man
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2024-04-25·CVSS 6.1
CVE-2024-3861 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2024-2609, CVE-2024-3852,
CVE-2024-3864)
Bartek Nowotarski discovered that Thunderbird did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)
Lukas Bernhard discovered that Thunderbird did not properly manage memory
during JIT optimisations, leading to an out-of-bounds read vulne
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2024-04-24·CVSS 3.7
CVE-2024-3853 [LOW] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-3852,
CVE-2024-3864, CVE-2024-3865)
Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)
Gary Kwong discovered that Firefox did not properly manage memory when
running garbage collection during realm initialization. An attacker could
potentially exploit this issue to cause a denial of service, or ex
Red Hat
Mozilla: Out-of-bounds-read after mis-optimized switch statement
vendor_redhat·2024-04-16·CVSS 8.8
CVE-2024-3854 [HIGH] CWE-125 Mozilla: Out-of-bounds-read after mis-optimized switch statement
Mozilla: Out-of-bounds-read after mis-optimized switch statement
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
The Mozilla Foundation Security Advisory describes this flaw as:
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2024-3854: firefox - In some code patterns the JIT incorrectly optimized switch statements and genera...
vendor_debian·2024·CVSS 8.8
CVE-2024-3854 [HIGH] CVE-2024-3854: firefox - In some code patterns the JIT incorrectly optimized switch statements and genera...
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Scope: local
sid: resolved (fixed in 125.0.1-1)
Mozilla
Mozilla Foundation Security Advisory 2024-19: CVE-2024-3854
vendor_mozilla·CVSS 8.8
CVE-2024-3854 [HIGH] Mozilla Foundation Security Advisory 2024-19: CVE-2024-3854
Mozilla Foundation Security Advisory 2024-19
CVE: CVE-2024-3854
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.10
Mozilla
Mozilla Foundation Security Advisory 2024-20: CVE-2024-3854
vendor_mozilla·CVSS 8.8
CVE-2024-3854 [HIGH] Mozilla Foundation Security Advisory 2024-20: CVE-2024-3854
Mozilla Foundation Security Advisory 2024-20
CVE: CVE-2024-3854
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 115.10
Mozilla
Mozilla Foundation Security Advisory 2024-18: CVE-2024-3854
vendor_mozilla·CVSS 8.8
CVE-2024-3854 [HIGH] Mozilla Foundation Security Advisory 2024-18: CVE-2024-3854
Mozilla Foundation Security Advisory 2024-18
CVE: CVE-2024-3854
Product: Firefox
Impact: high
Fixed in: Firefox 125
OSV
firefox regressions
osv·2024-05-02·CVSS 3.7
CVE-2024-3852 [LOW] firefox regressions
firefox regressions
USN-6747-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-3852,
CVE-2024-3864, CVE-2024-3865)
Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)
Gary Kwong discovered that Firefox did not properly manage memory when
running garbage collection during realm initialization
OSV
thunderbird vulnerabilities
osv·2024-04-25·CVSS 6.1
CVE-2024-2609 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2024-2609, CVE-2024-3852,
CVE-2024-3864)
Bartek Nowotarski discovered that Thunderbird did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)
Lukas Bernhard discovered that Thunderbird did not properly manage memory
during JIT optimisations, leading to an out-of-bounds read vulnerability.
An attacker could possibly use this issue to cause a denia
OSV
firefox vulnerabilities
osv·2024-04-24·CVSS 3.7
CVE-2024-3852 [LOW] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-3852,
CVE-2024-3864, CVE-2024-3865)
Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)
Gary Kwong discovered that Firefox did not properly manage memory when
running garbage collection during realm initialization. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-3853)
Lukas Bernhard discovered
GHSA
GHSA-xc66-q4x2-cwqx: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads
ghsa_unreviewed·2024-04-16
CVE-2024-3854 [HIGH] CWE-125 GHSA-xc66-q4x2-cwqx: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125 and Firefox ESR < 115.10.
OSV
CVE-2024-3854: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads
osv·2024-04-16·CVSS 8.8
CVE-2024-3854 [HIGH] CVE-2024-3854: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
No detection rules found.
No public exploits indexed.
Bugzilla
ZDI-CAN-29301: Mozilla Firefox IonMonkey Switch Statement Optimization Type Confusion Remote Code Execution Vulnerability
bugzilla·2026-03-04·CVSS 8.8
CVE-2024-3854 [HIGH] ZDI-CAN-29301: Mozilla Firefox IonMonkey Switch Statement Optimization Type Confusion Remote Code Execution Vulnerability
ZDI-CAN-29301: Mozilla Firefox IonMonkey Switch Statement Optimization Type Confusion Remote Code Execution Vulnerability
### Analysis
A type confusion vulnerability exists in the IonMonkey JIT compiler's MIR optimization pipeline. It is a variant of CVE-2024-3854 (`https://bugzilla.mozilla.org/show_bug.cgi?id=1884552`). Similar to the patched vulnerability in IsDiamondPattern, the IsTrianglePattern function uses `"numSuccessors() == 1"`, as it expects the graph block to end with the MGoto MIR node. However this is not always the case. An empty switch statement can be used to satisfy this expression, which results in a type confusion from MTableSwitch to MGoto. The `IsTrianglePattern` function checks whether a JIT graph block will only go to a single location using the expression `numSuc
Bugzilla
CVE-2023-52667 kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups
bugzilla·2024-05-18·CVSS 7.8
CVE-2023-52667 [HIGH] CVE-2023-52667 kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups
CVE-2023-52667 kernel: net/mlx5e: fix a potential double-free in fs_any_create_groups
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: fix a potential double-free in fs_any_create_groups
The Linux kernel CVE team has assigned CVE-2023-52667 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051728-CVE-2023-52667-649b@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281351]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:3854 https://access.redhat.com/errata/RHSA-2024:3854
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-20
Bugzilla
CVE-2023-5090 kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs
bugzilla·2023-11-06·CVSS 5.5
CVE-2023-5090 [MEDIUM] CVE-2023-5090 kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs
CVE-2023-5090 kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs
An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.
Upstream patch & commit:
https://lore.kernel.org/kvm/[email protected]/T
https://github.com/torvalds/linux/commit/b65235f6e102354ccafda601eaa1c5bef5284d21
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2248123]
---
This was fixed for Fedora with the 6.5.9 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:3854 https://
https://bugzilla.mozilla.org/show_bug.cgi?id=1884552https://lists.debian.org/debian-lts-announce/2024/04/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2024/04/msg00013.htmlhttps://www.mozilla.org/security/advisories/mfsa2024-18/https://www.mozilla.org/security/advisories/mfsa2024-19/https://www.mozilla.org/security/advisories/mfsa2024-20/https://bugzilla.mozilla.org/show_bug.cgi?id=1884552https://lists.debian.org/debian-lts-announce/2024/04/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2024/04/msg00013.htmlhttps://www.mozilla.org/security/advisories/mfsa2024-18/https://www.mozilla.org/security/advisories/mfsa2024-19/https://www.mozilla.org/security/advisories/mfsa2024-20/
2024-04-16
Published