CVE-2022-42930
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-42930 is a race condition vulnerability discovered in Firefox's DOM Workers component. The vulnerability was reported by Armin Ebert and fixed in Firefox 106, which was released on October 18, 2022. The issue affects Firefox versions prior to 106, where a data race could occur in the ThirdPartyUtil component when two Workers simultaneously initialized their CacheStorage (Mozilla Advisory).

Technical details

The vulnerability manifests when two Worker threads concurrently initialize their CacheStorage. Since CacheStorage is created lazily, the race condition occurs during the first access to the caches global object. The data race specifically happens in the XPCOMService_GetThirdPartyUtil component, affecting the ThirdPartyUtil initialization process. The issue was assigned a moderate severity rating by Mozilla (Mozilla Advisory).

Impact

The vulnerability has been classified with moderate severity impact. While the full extent of potential exploitation isn't detailed in public sources, the race condition in the ThirdPartyUtil component could potentially lead to inconsistent states or unexpected behavior in the browser's handling of third-party content (Mozilla Advisory).

Mitigation and workarounds

The vulnerability was fixed in Firefox version 106. Users and organizations running affected versions of Firefox should upgrade to Firefox 106 or later to mitigate this vulnerability. No specific workarounds were published for users unable to upgrade immediately (Mozilla Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61609HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management