CVE-2020-6820
Mozilla Thunderbird, Mozilla Firefox, Mozilla Firefox ESR
Published 24 Apr 2020 · updated 17 Jun 2026 · Analyzed
8.1 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
References
- bugzilla.mozilla.org/show_bug.cgi?id=1626728 · Issue Tracking, Permissions Required
- usn.ubuntu.com/4335-1/ · Third Party Advisory
- www.mozilla.org/security/advisories/mfsa2020-11/ · Vendor Advisory
- www.mozilla.org/security/advisories/mfsa2020-14/ · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6820 · US Government Resource