CVE-2021-29952
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-29952 is a race condition vulnerability discovered in Firefox's Web Render components. The vulnerability was disclosed on May 5, 2021, affecting Firefox versions prior to 88.0.1 and Firefox for Android versions prior to 88.1.3. When Web Render components were destructed, a race condition could have caused undefined behavior (Mozilla Advisory).

Technical details

The vulnerability is classified as a race condition (CWE-362) with a CVSS v3.1 base score of 7.5 (HIGH). The technical issue occurs when WebRenderBridgeParent::RecvShutdownSync() causes WebRenderBridgeParent::ClearResources() to run on the compositor thread, racing with the use of WebRender data structure on a WRScene~ilder thread (Bugzilla).

Impact

The race condition could potentially lead to undefined behavior and, with sufficient effort, could be exploited to execute arbitrary code. The vulnerability was rated as having a high impact by Mozilla's security team (Mozilla Advisory).

Exploitability

The vulnerability could occur during window closure or system shutdown. While rated as having high impact, the exploitation would require significant effort due to the nature of the race condition. The vulnerability was discovered through ThreadSanitizer analysis during fuzzing of the mozilla-central build (Bugzilla).

Mitigation and workarounds

The vulnerability was patched in Firefox 88.0.1 and Firefox for Android 88.1.3. Users should update to these versions or later to mitigate the risk. The fix involved moving more work to the compositor thread to avoid potential races (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management