CVE-2022-34480

Updated: 2025-08-20 03:06:33.857526

Description:

Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 8.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS nss 3.44.0 8.8 HIGH Not Vulnerable 2023-02-16 10:03:48
CentOS 8.4 ELS nss 3.67.0-6 8.8 HIGH Released CLSA-2023:1677783628 2023-03-02 16:04:17
CentOS 8.5 ELS nss 3.67.0-7 8.8 HIGH Released CLSA-2023:1677783798 2023-03-02 16:04:17
CloudLinux 6 ELS nss 3.44.0 8.8 HIGH Not Vulnerable 2023-02-16 10:03:48
Oracle Linux 6 ELS nss 3.44.0 8.8 HIGH Not Vulnerable 2023-02-16 10:03:48
Ubuntu 16.04 ELS nss 3.28.4-0 8.8 HIGH Released CLSA-2023:1677784062 2023-03-02 16:04:17