High severity8.8NVD Advisory· Published Dec 8, 2021· Updated Jun 17, 2026
CVE-2021-43535
CVE-2021-43535
Description
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5<93+ 2 more
- (no CPE)range: <93
- (no CPE)range: unspecified
- (no CPE)range: unspecified
<91.3+ 1 more
- (no CPE)range: <91.3
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
8- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- lists.debian.org/debian-lts-announce/2021/12/msg00030.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/01/msg00001.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2021/dsa-5026nvdThird Party Advisory
- www.debian.org/security/2022/dsa-5034nvdIssue TrackingThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2021-43/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2021-49/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2021-50/nvdVendor Advisory
News mentions
0No linked articles in our index yet.