CVE-2022-34480
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-34480 is a vulnerability discovered in Firefox versions prior to 102, reported by Ronald Crane. The vulnerability was disclosed on June 28, 2022, and affects the lg_init() function in Firefox's security component. This issue occurs when several allocations succeed but then one fails, resulting in an uninitialized pointer being freed despite never being allocated (Mozilla Advisory).

Technical details

The vulnerability exists within the lginit() function where if several memory allocations succeed but then one fails, an uninitialized pointer would be freed despite never being allocated. The issue specifically occurs when line 511 fails (such as with an Out of Memory condition), causing lines 512-14 to transfer control to lines 544 and subsequent lines, where line 552 would read the uninitialized pointer lgdb->hashtable. If this pointer is nonzero, line 553 would attempt to destroy it, potentially leading to memory corruption ([Mozilla Bug](https://bugzilla.mozilla.org/showbug.cgi?id=1454072)). The vulnerability has been assigned a low severity impact rating by Mozilla (Mozilla Advisory).

Impact

The vulnerability has been classified with a low impact severity. While it could lead to memory corruption, it was considered more of a bug than something that could be intentionally exploited, as it would require successfully getting past multiple PORTAllocs and then triggering an Out of Memory condition in exactly the right place ([Mozilla Bug](https://bugzilla.mozilla.org/showbug.cgi?id=1454072)).

Mitigation and workarounds

The vulnerability was fixed in Firefox version 102. Users should upgrade to Firefox 102 or later to receive the security fix. The fix was also backported to Firefox ESR versions (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61609HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management