CVE-2024-6605
published 2024-07-09CVE-2024-6605: Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 128.0 | 128.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 128 | 128 |
Red Hat
kernel: wireguard: receive: annotate data-race around receiving_counter.counter
vendor_redhat·2024-04-17·CVSS 4.7
CVE-2024-26861 [MEDIUM] CWE-362 kernel: wireguard: receive: annotate data-race around receiving_counter.counter
kernel: wireguard: receive: annotate data-race around receiving_counter.counter
In the Linux kernel, the following vulnerability has been resolved:
wireguard: receive: annotate data-race around receiving_counter.counter
Syzkaller with KCSAN identified a data-race issue when accessing
keypair->receiving_counter.counter. Use READ_ONCE() and WRITE_ONCE()
annotations to mark the data race as intentional.
BUG: KCSAN: data-race in wg_packet_decrypt_worker / wg_packet_rx_poll
write to 0xffff888107765888 of 8 bytes by interrupt on cpu 0:
counter_validate drivers/net/wireguard/receive.c:321 [inline]
wg_packet_rx_poll+0x3ac/0xf00 drivers/net/wireguard/receive.c:461
__napi_poll+0x60/0x3b0 net/core/dev.c:6536
napi_poll net/core/dev.c:6605 [inline]
net_rx_action+0x32b/0x750 net/core/dev.c:6738
__do_so
Debian
CVE-2024-6605: firefox - Firefox Android allowed immediate interaction with permission prompts. This coul...
vendor_debian·2024·CVSS 8.8
CVE-2024-6605 [HIGH] CVE-2024-6605: firefox - Firefox Android allowed immediate interaction with permission prompts. This coul...
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-29: CVE-2024-6605
vendor_mozilla·CVSS 8.8
CVE-2024-6605 [HIGH] Mozilla Foundation Security Advisory 2024-29: CVE-2024-6605
Mozilla Foundation Security Advisory 2024-29
CVE: CVE-2024-6605
Product: Firefox
Impact: high
Fixed in: Firefox 128
GHSA
GHSA-cpfv-mr66-74v6: Firefox Android allowed immediate interaction with permission prompts
ghsa_unreviewed·2024-07-09
CVE-2024-6605 [HIGH] CWE-277 GHSA-cpfv-mr66-74v6: Firefox Android allowed immediate interaction with permission prompts
Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.
No detection rules found.
No public exploits indexed.
2024-07-09
Published