CVE-2020-6807: Use After Free
Last updated 25 August 2025
Other sources
When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2020-09/#CVE-2020-6807
— Red Hat
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
— Launchpad
When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-6807?
CVE-2020-6807 is a vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird that could lead to a use-after-free and potentially exploitable crash.
How does CVE-2020-6807 occur?
CVE-2020-6807 occurs when a device is changed while a stream is being destroyed in Mozilla Firefox, Firefox ESR, or Thunderbird.
Which software versions are affected by CVE-2020-6807?
Mozilla Firefox version up to 74, Firefox ESR version up to 68.6, and Thunderbird version up to 68.6 are affected by CVE-2020-6807.
What is the severity of CVE-2020-6807?
CVE-2020-6807 is classified as high severity with a severity value of 7.
How can CVE-2020-6807 be fixed?
To fix CVE-2020-6807, users should update to the latest versions of Mozilla Firefox, Firefox ESR, or Thunderbird.