Bug 1196809 - (CVE-2022-26485) VUL-0: CVE-2022-26485,CVE-2022-26486: MozillaFirefox,MozillaThunderbird: Removing an XSLT parameter during processing could lead to an exploitable use-after-free
(CVE-2022-26485)
VUL-0: CVE-2022-26485,CVE-2022-26486: MozillaFirefox,MozillaThunderbird: Remo...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P1 - Urgent : Critical
: ---
Assigned To: Mozilla Bugs
Security Team bot
https://smash.suse.de/issue/325437/
CVSSv3.1:SUSE:CVE-2022-26485:8.8:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-03-07 08:01 UTC by Gianluca Gabrielli
Modified: 2022-09-26 09:11 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gianluca Gabrielli 2022-03-07 08:01:52 UTC
#CVE-2022-26485: Use-after-free in XSLT parameter processing
Impact
    critical
Description
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw.

#CVE-2022-26486: Use-after-free in WebGPU IPC Framework
Impact
    critical
Description
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw.

Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/
Comment 1 Gianluca Gabrielli 2022-03-07 08:02:31 UTC
Please update to Firefox 97.0.2 or Firefox ESR 91.6.1
Comment 2 Gianluca Gabrielli 2022-03-07 08:50:14 UTC
Supported packages:
 - SUSE:SLE-11-SP1:Update/MozillaFirefox   91.6.0
 - SUSE:SLE-12-SP2:Update/MozillaFirefox   91.6.0
 - SUSE:SLE-15-SP2:Update/MozillaFirefox   91.6.0
 - SUSE:SLE-15:Update/MozillaFirefox       91.6.0
 - openSUSE:Factory/MozillaFirefox         97.0.1
Comment 6 Gianluca Gabrielli 2022-03-08 08:42:43 UTC
MozillaThunderbird is affected as well, please update to 91.6.2.
Comment 7 hui 2022-03-08 19:29:48 UTC
Mozilla released Firefox ESR 91.7 and Firefox 98 today with following fixes:

CVE-2022-26383: Browser window spoof using fullscreen mode
CVE-2022-26384: iframe allow-scripts sandbox bypass
CVE-2022-26387: Time-of-check time-of-use bug when verifying add-on signatures
CVE-2022-26381: Use-after-free in text reflows
CVE-2022-26386: Temporary files downloaded to /tmp and accessible by other local users
CVE-2022-26382: Autofill Text could be exfiltrated via side-channel attacks
CVE-2022-26385: Use-after-free in thread shutdown
CVE-2022-0843: Memory safety bugs fixed in Firefox 98

When can we expect an update for the bugs which get attacked in the wild?
Comment 9 Marcus Meissner 2022-03-09 08:00:54 UTC
updates are now in QA, likely goingto be released today.
Comment 10 Marcus Meissner 2022-03-09 08:28:29 UTC
i put the 91.7/98 into a new tracker bug, bug 1196900
Comment 12 Swamp Workflow Management 2022-03-09 17:20:51 UTC
openSUSE-SU-2022:0783-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1196809
CVE References: CVE-2022-26485,CVE-2022-26486
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    MozillaFirefox-91.6.1-152.19.1
openSUSE Leap 15.3 (src):    MozillaFirefox-91.6.1-152.19.1
Comment 13 Swamp Workflow Management 2022-03-09 17:21:41 UTC
SUSE-SU-2022:0783-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1196809
CVE References: CVE-2022-26485,CVE-2022-26486
JIRA References: 
Sources used:
SUSE Manager Server 4.1 (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Manager Retail Branch Server 4.1 (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Manager Proxy 4.1 (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Linux Enterprise Server 15-SP2-BCL (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Linux Enterprise Realtime Extension 15-SP2 (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    MozillaFirefox-91.6.1-152.19.1
SUSE Enterprise Storage 7 (src):    MozillaFirefox-91.6.1-152.19.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Swamp Workflow Management 2022-03-09 17:23:28 UTC
SUSE-SU-2022:0777-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1196809
CVE References: CVE-2022-26485,CVE-2022-26486
JIRA References: 
Sources used:
SUSE OpenStack Cloud Crowbar 9 (src):    MozillaFirefox-91.6.1-112.92.1
SUSE OpenStack Cloud Crowbar 8 (src):    MozillaFirefox-91.6.1-112.92.1
SUSE OpenStack Cloud 9 (src):    MozillaFirefox-91.6.1-112.92.1
SUSE OpenStack Cloud 8 (src):    MozillaFirefox-91.6.1-112.92.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    MozillaFirefox-91.6.1-112.92.1
SUSE Linux Enterprise Server for SAP 12-SP4 (src):    MozillaFirefox-91.6.1-112.92.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    MozillaFirefox-91.6.1-112.92.1
SUSE Linux Enterprise Server 12-SP5 (src):    MozillaFirefox-91.6.1-112.92.1
SUSE Linux Enterprise Server 12-SP4-LTSS (src):    MozillaFirefox-91.6.1-112.92.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    MozillaFirefox-91.6.1-112.92.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    MozillaFirefox-91.6.1-112.92.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    MozillaFirefox-91.6.1-112.92.1
HPE Helion Openstack 8 (src):    MozillaFirefox-91.6.1-112.92.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Swamp Workflow Management 2022-03-09 17:25:18 UTC
SUSE-SU-2022:0778-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1196809
CVE References: CVE-2022-26485,CVE-2022-26486
JIRA References: 
Sources used:
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Linux Enterprise Server for SAP 15 (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Linux Enterprise Server 15-LTSS (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    MozillaFirefox-91.6.1-150.21.1
SUSE Enterprise Storage 6 (src):    MozillaFirefox-91.6.1-150.21.1
SUSE CaaS Platform 4.0 (src):    MozillaFirefox-91.6.1-150.21.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Swamp Workflow Management 2022-03-10 20:18:29 UTC
openSUSE-SU-2022:0804-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1196809
CVE References: CVE-2022-26485,CVE-2022-26486
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    MozillaThunderbird-91.6.2-8.59.1
openSUSE Leap 15.3 (src):    MozillaThunderbird-91.6.2-8.59.1
Comment 18 Swamp Workflow Management 2022-03-10 20:19:33 UTC
SUSE-SU-2022:0804-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1196809
CVE References: CVE-2022-26485,CVE-2022-26486
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 15-SP3 (src):    MozillaThunderbird-91.6.2-8.59.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    MozillaThunderbird-91.6.2-8.59.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 19 Swamp Workflow Management 2022-03-11 17:17:43 UTC
SUSE-SU-2022:14906-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1196809,1196900
CVE References: CVE-2022-26381,CVE-2022-26383,CVE-2022-26384,CVE-2022-26386,CVE-2022-26387,CVE-2022-26485,CVE-2022-26486
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    MozillaFirefox-91.7.0-78.167.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    MozillaFirefox-91.7.0-78.167.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 20 hui 2022-03-14 16:26:57 UTC
7 days after this bug was opened and 9 days after Mozilla released a patched version (91.6.2) for Thunderbird, Tumbleweed still ships Thunderbird 91.6.1 which has critical security holes (whilst attacks in the wild abusing open flaws).
In the meantime Mozilla released another update with more fixes (91.7).

I don't want to complain but even distributions with 0,01% manpower compared to SUSE are able to provide a security fix faster than Suse. What a shame.

Mageia
thunderbird-91.7.0 Thu Mar 10
thunderbird-91.6.2 Mon Mar 7

Fedora
thunderbird-91.6.2 Mon Mar 7
Comment 23 Andreas Stieger 2022-09-26 09:11:30 UTC
done