CVE-2016-2828: Canonical Ubuntu Linux
High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Mozilla Firefox: up to and including 46.0.1; version 45.1.0 only; version 45.1.1 only
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
Published 2016-06-13. Last modified 2026-06-17.