CVE-2021-29984
Description
Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2021:3155
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2021:3157
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-29984
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-29984.html
Vendor advisory: arch — https://security.archlinux.org/ASA-202108-14
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 78.13.0-1 | |
| sles | affected | | |
| debian | sid | fixed | 91.0-1 |
| debian | bookworm | fixed | 78.13.0esr-1 |
| debian | bullseye | fixed | 78.13.0esr-1~deb11u1 |
| debian | forky | fixed | 78.13.0esr-1 |
| debian | trixie | fixed | 78.13.0esr-1 |
| rocky | 8 | fixed | |
References
Verify integrity in audit chain (admin only). AS-IS.