Vulnerability CVE-2024-11704: Information

Description

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.

Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Nov. 26, 2024
Modified: June 17, 2026
Error type identifier: CWE-415

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus133.0.0-alt1152.0.6-alt1ALT-PU-2024-16341-3363536Fixed
firefoxsisyphus_riscv64133.0.3-alt0.port152.0.4-alt0.portALT-PU-2024-17555-1-Fixed
firefoxsisyphus_loongarch64133.0.3-alt0.port152.0.4-alt0.portALT-PU-2024-17515-1-Fixed
firefoxp11133.0.0-alt1152.0.4-alt1ALT-PU-2024-16375-4363732Fixed
firefoxp10134.0.2-alt0.p10.1141.0.2-alt0.p10.1ALT-PU-2025-2230-4372243Fixed
firefox-esrsisyphus128.7.0-alt1140.12.0-alt1ALT-PU-2025-2782-3374549Fixed
firefox-esrsisyphus_loongarch64128.8.1-alt0.port140.9.1-alt0.portALT-PU-2025-5491-1-Fixed
firefox-esrp11128.7.0-alt1140.12.0-alt1ALT-PU-2025-2842-4374623Fixed
firefox-esrp10128.7.0-alt1140.12.0-alt0.p10.1ALT-PU-2025-3294-4375522Fixed
firefox-esrc10f2128.10.1-alt0.c10.1140.12.0-alt1ALT-PU-2025-8709-4388123Fixed
palemoonsisyphus33.5.1-alt134.3.1-alt1ALT-PU-2025-1567-4370544Fixed
palemoonp1133.6.0-alt134.3.1-alt1ALT-PU-2025-2672-4374394Fixed
palemoonp1033.7.1-alt133.7.1-alt1ALT-PU-2025-8904-2384191Fixed
palemoonc10f233.8.1.2-alt133.8.1.2-alt1ALT-PU-2025-10922-3393313Fixed
thunderbirdsisyphus128.7.0-alt1152.0.1-alt1ALT-PU-2025-2615-3374232Fixed
thunderbirdsisyphus_riscv64128.7.0-alt1151.0.1-alt1ALT-PU-2025-2688-1-Fixed
thunderbirdsisyphus_loongarch64128.7.0-alt1152.0.1-alt1ALT-PU-2025-2638-1-Fixed
thunderbirdp11128.8.0-alt1152.0-alt1ALT-PU-2025-4001-4377410Fixed
thunderbirdp10138.0-alt1.p10.1145.0-alt0.p10.1ALT-PU-2025-7695-3385484Fixed
thunderbirdc10f2141.0-alt0.p10.1145.0-alt0.p10.1ALT-PU-2025-11560-14394393Fixed

References to Advisories, Solutions, and Tools

    1. cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
      End excluding
      128.7.0

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excluding
      133.0

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      End excluding
      128.7.0

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      Start including
      129.0
      End excluding
      133.0