Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
https://bugzilla.mozilla.org/show_bug.cgi?id=1620818
https://www.mozilla.org/security/advisories/mfsa2020-11/
https://www.mozilla.org/security/advisories/mfsa2020-14/
https://usn.ubuntu.com/4335-1/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6819