CVE-2022-38476
Summary
| CVE | CVE-2022-38476 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 20:15:00 UTC |
| Updated | 2023-01-03 20:51:00 UTC |
| Description | A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160060 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-6169)
- 160062 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-6165)
- 160063 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-6175)
- 160065 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-6164)
- 160068 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-6174)
- 160070 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-6179)
- 184054 Debian Security Update for firefox-esrthunderbird (CVE-2022-38476)
- 198977 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5663-1)
- 240618 Red Hat Update for firefox (RHSA-2022:6174)
- 240619 Red Hat Update for thunderbird (RHSA-2022:6165)
- 240620 Red Hat Update for thunderbird (RHSA-2022:6169)
- 240621 Red Hat Update for thunderbird (RHSA-2022:6164)
- 240622 Red Hat Update for firefox (RHSA-2022:6175)
- 240624 Red Hat Update for thunderbird (RHSA-2022:6168)
- 240628 Red Hat Update for thunderbird (RHSA-2022:6166)
- 240629 Red Hat Update for firefox (RHSA-2022:6176)
- 240631 Red Hat Update for firefox (RHSA-2022:6179)
- 240632 Red Hat Update for firefox (RHSA-2022:6177)
- 257190 CentOS Security Update for firefox (CESA-2022:6179)
- 257193 CentOS Security Update for thunderbird (CESA-2022:6169)
- 354078 Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1855
- 356231 Amazon Linux Security Advisory for firefox : ALASFIREFOX-2023-012
- 376859 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2022-34)
- 376861 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2022-36)
- 503449 Alpine Linux Security Update for firefox-esr
- 506057 Alpine Linux Security Update for firefox-esr
- 710610 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202208-37)
- 710612 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202208-38)
- 752583 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3273-1)
- 752590 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3272-1)
- 752611 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3396-1)
- 753189 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2022:3281-1)
- 940644 AlmaLinux Security Update for firefox (ALSA-2022:6175)
- 940645 AlmaLinux Security Update for thunderbird (ALSA-2022:6164)
- 940647 AlmaLinux Security Update for thunderbird (ALSA-2022:6165)
- 940648 AlmaLinux Security Update for firefox (ALSA-2022:6174)
- 960291 Rocky Linux Security Update for thunderbird (RLSA-2022:6164)
- 960360 Rocky Linux Security Update for firefox (RLSA-2022:6175)