CVE-2024-3854: High severity thunderbird vulnerability
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3854?
CVE-2024-3854 has been classified with a high severity due to its potential for causing out-of-bounds reads.
How do I fix CVE-2024-3854?
To fix CVE-2024-3854, users should update to the latest version of affected software such as Firefox, Thunderbird, or Firefox ESR, depending on their distribution.
Which versions are affected by CVE-2024-3854?
CVE-2024-3854 affects Firefox and Thunderbird versions earlier than 115.10, as well as Firefox ESR versions earlier than 115.10.
What products are impacted by CVE-2024-3854?
CVE-2024-3854 impacts Mozilla's Firefox, Firefox ESR, and Thunderbird across various Linux distributions.
Is there a workaround for CVE-2024-3854?
Currently, the best approach for mitigating CVE-2024-3854 is to upgrade to a patched version of the affected software.