Race condition in Mozilla Firefox - CVE-2021-29952
Published: May 5, 2021
Vulnerability identifier: #VU52899
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-29952
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in Web Render components. A remote attacker can create a specially crafted web page, trick the victim into opening it and execute arbitrary code on the system.
Affected software
Mozilla Firefox
Arch Linux
Ubuntu
Fedora
Firefox for Android
firefox
firefox (Ubuntu package)
Arch Linux
Ubuntu
Fedora
Firefox for Android
firefox
firefox (Ubuntu package)
How to mitigate CVE-2021-29952
Install updates from vendor's website.
Mozilla Firefox - update to 88.0.1
Firefox for Android - update to 88.1.3
firefox - addressed in versions stable-3420210510090803.1, 88.0.1-1.fc33, 88.0.1-1.fc34
firefox (Ubuntu package) - addressed in versions 88.0.1+build1-0ubuntu0.18.04.2, 88.0.1+build1-0ubuntu0.20.04.2, 88.0.1+build1-0ubuntu0.20.10.2, 88.0.1+build1-0ubuntu0.21.04.2
Firefox for Android - update to 88.1.3
firefox - addressed in versions stable-3420210510090803.1, 88.0.1-1.fc33, 88.0.1-1.fc34
firefox (Ubuntu package) - addressed in versions 88.0.1+build1-0ubuntu0.18.04.2, 88.0.1+build1-0ubuntu0.20.04.2, 88.0.1+build1-0ubuntu0.20.10.2, 88.0.1+build1-0ubuntu0.21.04.2