UBUNTU-CVE-2023-5170

Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 28 Sept 2023, 00:00
Last modified:04 Feb 2026, 04:24

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.4 HIGH
3.1 (osv_ubuntu)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 Sept 2023, 00:00
Published
Vulnerability first disclosed
04 Feb 2026, 04:24
Last Modified
Vulnerability information updated

Description

In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.

CVSS Metrics

  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Affected Systems

  • ubuntufirefox

    < 118.0.1+build1-0ubuntu0.20.04.1

  • ubuntumozjs102

    all | all

  • ubuntumozjs38

    all

  • ubuntumozjs52

    all | all

  • ubuntumozjs68

    all

  • ubuntumozjs78

    all

  • ubuntumozjs91

    all

References (6)