CVE-2021-29968
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-29968 is a security vulnerability discovered in Mozilla Firefox that affects versions prior to 89.0.1. The vulnerability was identified when drawing text onto a canvas with WebRender disabled, which could result in an out-of-bounds read. This security issue specifically affects Firefox running on Windows operating systems, while other operating systems remain unaffected (Mozilla Advisory, NVD).

Technical details

The vulnerability is classified as an out-of-bounds read vulnerability (CWE-125) that occurs during text rendering operations when WebRender is disabled. The issue received a CVSS v3.1 base score of 8.1 (HIGH) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H. The vulnerability was specifically tied to the interaction between Direct2D and Skia when WebRender was disabled (NVD).

Impact

The vulnerability could lead to memory corruption and potentially result in crashes when users interact with affected web content. For affected Windows users, certain websites could become unusable due to reliable triggering of the vulnerability. The issue was particularly impactful as it represented approximately 3% of crashes on the release version, making it one of the top 5 crashers for Firefox 89 (Mozilla Bug).

Mitigation and workarounds

Mozilla addressed this vulnerability in Firefox version 89.0.1. As an additional mitigation measure, Mozilla implemented a blocklist entry for D2D on the affected hardware to reduce crash occurrences. Users were advised to update to Firefox 89.0.1 or later to resolve the issue (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61609HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management