CVE-2015-1243: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an attempt to unregister a MutationObserver object that is not currently registered.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 14.10 only; version 15.04 only
  • Debian Debian Linux: version 8.0 only
  • Google Chrome: up to and including 42.0.2311.87
  • Red Hat Enterprise Linux Desktop Supplementary: version 6.0 only
  • Red Hat Enterprise Linux Server Supplementary: version 6.0 only
  • Red Hat Enterprise Linux Server Supplementary Eus: version 6.6.z only
  • Red Hat Enterprise Linux Workstation Supplementary: version 6.0 only

Published 2015-05-01. Last modified 2026-06-17.