Low firefox Memory Corruption

Overview

Low
Severity
CVSS
No
Exploited ITW
Embargoed
Fix Status
Impactlow
DescriptionA double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption.
ComponentCore
Bug ClassMemory Corruption
Tracker1899402
CISA KEVNot listed
CreditedRonald Crane
Disclosed2024-11-26

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.
On This Page