CVE-2018-18504: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This results is a potentially exploitable crash and the possibility of reading from the memory of the freed buffers. This vulnerability affects Firefox < 65.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Mozilla Firefox: before 65.0 (fixed in 65.0)

Published 2019-02-05. Last modified 2026-06-17.