Mozilla: Incorrect code generation during JIT compilation
Published Jun 2, 2023
7.5
HIGHCVSS 3.1
EPSS 0.69%
Description
Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Affected products
-
Affected
- ≥ unspecified, < 111
-
Affected
- ≥ unspecified, < 102.9
-
Affected
- ≥ unspecified, < 102.9
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mozilla | Firefox | unknown | Affected
|
| Mozilla | Firefox ESR | unknown | Affected
|
| Mozilla | Thunderbird | unknown | Affected
|
- < 111.0
- < 102.9
- < 102.9
No data.
Red Hat Enterprise Linux 7
firefox-0:102.9.0-3.el7_9
Fixed · RHSA-2023:1333
Red Hat Enterprise Linux 7
thunderbird-0:102.9.0-1.el7_9
Fixed · RHSA-2023:1401
Red Hat Enterprise Linux 8
firefox-0:102.9.0-3.el8_7
Fixed · RHSA-2023:1336
Red Hat Enterprise Linux 8
thunderbird-0:102.9.0-1.el8_7
Fixed · RHSA-2023:1403
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
firefox-0:102.9.0-4.el8_1
Fixed · RHSA-2023:1479
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
thunderbird-0:102.9.0-2.el8_1
Fixed · RHSA-2023:1442
Red Hat Enterprise Linux 8.2 Advanced Update Support
firefox-0:102.9.0-4.el8_2
Fixed · RHSA-2023:1445
Red Hat Enterprise Linux 8.2 Advanced Update Support
thunderbird-0:102.9.0-2.el8_2
Fixed · RHSA-2023:1443
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
firefox-0:102.9.0-4.el8_2
Fixed · RHSA-2023:1445
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
thunderbird-0:102.9.0-2.el8_2
Fixed · RHSA-2023:1443
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
firefox-0:102.9.0-4.el8_2
Fixed · RHSA-2023:1445
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
thunderbird-0:102.9.0-2.el8_2
Fixed · RHSA-2023:1443
Red Hat Enterprise Linux 8.4 Extended Update Support
firefox-0:102.9.0-4.el8_4
Fixed · RHSA-2023:1444
Red Hat Enterprise Linux 8.4 Extended Update Support
thunderbird-0:102.9.0-2.el8_4
Fixed · RHSA-2023:1472
Red Hat Enterprise Linux 8.6 Extended Update Support
firefox-0:102.9.0-3.el8_6
Fixed · RHSA-2023:1367
Red Hat Enterprise Linux 8.6 Extended Update Support
thunderbird-0:102.9.0-1.el8_6
Fixed · RHSA-2023:1404
Red Hat Enterprise Linux 9
firefox-0:102.9.0-3.el9_1
Fixed · RHSA-2023:1337
Red Hat Enterprise Linux 9
thunderbird-0:102.9.0-1.el9_1
Fixed · RHSA-2023:1407
Red Hat Enterprise Linux 9.0 Extended Update Support
firefox-0:102.9.0-3.el9_0
Fixed · RHSA-2023:1364
Red Hat Enterprise Linux 9.0 Extended Update Support
thunderbird-0:102.9.0-1.el9_0
Fixed · RHSA-2023:1402
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | firefox-0:102.9.0-3.el7_9 | Fixed | RHSA-2023:1333 |
| Red Hat Enterprise Linux 7 | thunderbird-0:102.9.0-1.el7_9 | Fixed | RHSA-2023:1401 |
| Red Hat Enterprise Linux 8 | firefox-0:102.9.0-3.el8_7 | Fixed | RHSA-2023:1336 |
| Red Hat Enterprise Linux 8 | thunderbird-0:102.9.0-1.el8_7 | Fixed | RHSA-2023:1403 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | firefox-0:102.9.0-4.el8_1 | Fixed | RHSA-2023:1479 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | thunderbird-0:102.9.0-2.el8_1 | Fixed | RHSA-2023:1442 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | firefox-0:102.9.0-4.el8_2 | Fixed | RHSA-2023:1445 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | thunderbird-0:102.9.0-2.el8_2 | Fixed | RHSA-2023:1443 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | firefox-0:102.9.0-4.el8_2 | Fixed | RHSA-2023:1445 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | thunderbird-0:102.9.0-2.el8_2 | Fixed | RHSA-2023:1443 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | firefox-0:102.9.0-4.el8_2 | Fixed | RHSA-2023:1445 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | thunderbird-0:102.9.0-2.el8_2 | Fixed | RHSA-2023:1443 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | firefox-0:102.9.0-4.el8_4 | Fixed | RHSA-2023:1444 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | thunderbird-0:102.9.0-2.el8_4 | Fixed | RHSA-2023:1472 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | firefox-0:102.9.0-3.el8_6 | Fixed | RHSA-2023:1367 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | thunderbird-0:102.9.0-1.el8_6 | Fixed | RHSA-2023:1404 |
| Red Hat Enterprise Linux 9 | firefox-0:102.9.0-3.el9_1 | Fixed | RHSA-2023:1337 |
| Red Hat Enterprise Linux 9 | thunderbird-0:102.9.0-1.el9_1 | Fixed | RHSA-2023:1407 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | firefox-0:102.9.0-3.el9_0 | Fixed | RHSA-2023:1364 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | thunderbird-0:102.9.0-1.el9_0 | Fixed | RHSA-2023:1402 |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
References (11)
- https://access.redhat.com/security/cve/CVE-2023-25751 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1814899 Issue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2178458 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-29658 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-25751
- https://www.cve.org/CVERecord?id=CVE-2023-25751
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-10/#CVE-2023-25751
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-11/#CVE-2023-25751
- https://www.mozilla.org/security/advisories/mfsa2023-09/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-10/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-11/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-25751 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1814899 | Issue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2178458 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-29658 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-25751 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-25751 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2023-10/#CVE-2023-25751 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2023-11/#CVE-2023-25751 | ||
| https://www.mozilla.org/security/advisories/mfsa2023-09/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2023-10/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2023-11/ | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data