CVE-2024-3857: Use After Free
Last updated 24 July 2024
Other sources
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3857?
CVE-2024-3857 has the potential for significant impact as it may lead to use-after-free crashes in affected software.
How do I fix CVE-2024-3857?
To fix CVE-2024-3857, update to the latest versions of the affected software, such as Firefox and Thunderbird, specifically beyond version 115.10.
Which products are affected by CVE-2024-3857?
CVE-2024-3857 affects versions of Firefox, Thunderbird, Firefox ESR, and the corresponding Debian packages up to version 115.10.
What causes the CVE-2024-3857 vulnerability?
The vulnerability in CVE-2024-3857 is caused by the JIT compiler generating incorrect code for arguments, resulting in potential crashes.
How can I check if my software is affected by CVE-2024-3857?
You can check if your software is affected by CVE-2024-3857 by comparing your installed version of Firefox or Thunderbird against the mentioned vulnerable versions.