In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1846686 | issue tracking permissions required |
https://www.mozilla.org/security/advisories/mfsa2023-41/ | vendor advisory |
https://security.gentoo.org/glsa/202401-10 |