Unrated severityNVD Advisory· Published Sep 11, 2023· Updated Dec 18, 2025
Memory corruption in JIT UpdateRegExpStatics
CVE-2023-4577
Description
When UpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
Affected products
34- osv-coords31 versionspkg:rpm/almalinux/firefoxpkg:rpm/almalinux/firefox-x11pkg:rpm/almalinux/thunderbirdpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP5
< 102.15.0-1.el8_8.alma+ 30 more
- (no CPE)range: < 102.15.0-1.el8_8.alma
- (no CPE)range: < 102.15.0-1.el9_2.alma
- (no CPE)range: < 102.15.0-1.el8_8.alma
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 117.0-1.1
- (no CPE)range: < 115.2.2-150200.8.130.1
- (no CPE)range: < 115.2.2-150200.8.130.1
- (no CPE)range: < 115.2.0-1.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150000.150.100.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-112.176.1
- (no CPE)range: < 115.2.0-150000.150.100.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-112.176.1
- (no CPE)range: < 115.2.0-150000.150.100.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-150200.152.102.1
- (no CPE)range: < 115.2.0-112.176.1
- (no CPE)range: < 115.2.2-150200.8.130.1
- (no CPE)range: < 115.2.2-150200.8.130.1
- (no CPE)range: < 115.2.2-150200.8.130.1
- (no CPE)range: < 115.2.2-150200.8.130.1
- Range: unspecified
- Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.