CVE-2022-29910
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-29910 is a security vulnerability affecting Firefox for Android that was discovered and fixed in Firefox version 100. When the application was closed or sent to the background, Firefox for Android would not properly record and persist HTTP Strict Transport Security (HSTS) settings. This vulnerability was specific to Firefox for Android, with other operating systems being unaffected (Mozilla Advisory).

Technical details

The vulnerability stems from an issue where the SiteSecurityServiceState.txt file in the profile directory, which stores HSTS policies, was only written out every 5 minutes and at shutdown. On mobile devices, sessions could be shorter than this interval, and without a proper shutdown hook, the HSTS settings would not be saved. The issue was assigned a CVSS v3.1 base score of 6.1 (Medium) (NVD, Mozilla Bug).

Impact

The vulnerability could lead to security implications where HSTS policies were not properly enforced after the browser was restarted or backgrounded. This meant that secure HTTPS connections might not be automatically enforced for websites that had previously set HSTS policies, potentially exposing users to downgrade attacks (Mozilla Advisory).

Mitigation and workarounds

The issue was fixed in Firefox 100 by implementing atomic writes for DataStorage data and adding a mechanism to trigger writes when the application is backgrounded. The fix ensures that HSTS settings are properly persisted even when the application is backgrounded or closed (Mozilla Bug).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68120MEDIUM5.4
  • NixOSNixOS
  • go
NoYesDec 30, 2025
CVE-2025-69413MEDIUM5.3
  • NixOSNixOS
  • code.gitea.io/gitea
NoYesJan 01, 2026
CVE-2025-15412MEDIUM4.8
  • NixOSNixOS
  • wabt
NoNoJan 01, 2026
CVE-2025-15411MEDIUM4.8
  • NixOSNixOS
  • wabt
NoNoJan 01, 2026
CVE-2025-68932LOW2.9
  • NixOSNixOS
  • freshrss
NoYesDec 27, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management