CVE-2022-40957

Summary

CVECVE-2022-40957
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2022-12-22 20:15:00 UTC
Updated2023-01-04 03:54:00 UTC
DescriptionInconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

Risk And Classification

Problem Types: NVD-CWE-noinfo

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Mozilla Firefox All All All All
Application Mozilla Firefox Esr All All All All
Application Mozilla Thunderbird All All All All

References

ReferenceSourceLinkTags
Security Vulnerabilities fixed in Thunderbird 102.3 — Mozilla MISC www.mozilla.org
Access Denied MISC bugzilla.mozilla.org
Security Vulnerabilities fixed in Firefox ESR 102.3 — Mozilla MISC www.mozilla.org
Security Vulnerabilities fixed in Firefox 105 — Mozilla MISC www.mozilla.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 160114 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-6708)
  • 160115 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-6702)
  • 160116 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-6717)
  • 160117 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-6700)
  • 160176 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2022-6710)
  • 160179 Oracle Enterprise Linux Security Update for firefox (ELSA-2022-6711)
  • 181074 Debian Security Update for firefox-esr (DSA 5237-1)
  • 181076 Debian Security Update for firefox-esr (DLA 3121-1)
  • 181078 Debian Security Update for thunderbird (DLA 3123-1)
  • 181080 Debian Security Update for thunderbird (DSA 5238-1)
  • 182958 Debian Security Update for firefox-esrthunderbird (CVE-2022-40957)
  • 198968 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5649-1)
  • 199024 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5724-1)
  • 240687 Red Hat Update for thunderbird (RHSA-2022:6708)
  • 240688 Red Hat Update for thunderbird (RHSA-2022:6713)
  • 240689 Red Hat Update for firefox (RHSA-2022:6700)
  • 240690 Red Hat Update for firefox (RHSA-2022:6707)
  • 240691 Red Hat Update for thunderbird (RHSA-2022:6717)
  • 240692 Red Hat Update for firefox (RHSA-2022:6702)
  • 240693 Red Hat Update for thunderbird (RHSA-2022:6710)
  • 240694 Red Hat Update for thunderbird (RHSA-2022:6715)
  • 240695 Red Hat Update for firefox (RHSA-2022:6711)
  • 240696 Red Hat Update for firefox (RHSA-2022:6701)
  • 354131 Amazon Linux Security Advisory for thunderbird : ALAS2-2022-1900
  • 356274 Amazon Linux Security Advisory for firefox : ALASFIREFOX-2023-010
  • 356488 Amazon Linux Security Advisory for firefox : ALAS2FIREFOX-2023-010
  • 377599 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2022-41)
  • 377600 Mozilla Firefox Multiple Vulnerabilities (MFSA2022-40)
  • 377602 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2022-42)
  • 503450 Alpine Linux Security Update for firefox-esr
  • 506058 Alpine Linux Security Update for firefox-esr
  • 710629 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202209-27)
  • 710635 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202209-18)
  • 752611 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3396-1)
  • 752626 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3440-1)
  • 752627 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3441-1)
  • 753237 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2022:3800-1)
  • 940675 AlmaLinux Security Update for firefox (ALSA-2022:6702)
  • 940676 AlmaLinux Security Update for thunderbird (ALSA-2022:6708)
  • 940683 AlmaLinux Security Update for firefox (ALSA-2022:6700)
  • 940694 AlmaLinux Security Update for thunderbird (ALSA-2022:6717)
  • 960288 Rocky Linux Security Update for firefox (RLSA-2022:6702)
  • 960388 Rocky Linux Security Update for thunderbird (RLSA-2022:6708)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report