Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6
Published Jan 7, 2025
7.5
HIGHCVSS 3.1
EPSS 0.25%
Description
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
Affected products
No data.
- < 128.6.0
- < 133.0
- < 128.6.0
- ≥ 129.0 · < 134.0
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
firefox-0:128.6.0-1.el7_9
Fixed · RHSA-2025:0132
Red Hat Enterprise Linux 8
firefox-0:128.6.0-1.el8_10
Fixed · RHSA-2025:0144
Red Hat Enterprise Linux 8
thunderbird-0:128.6.0-3.el8_10
Fixed · RHSA-2025:0281
Red Hat Enterprise Linux 8.2 Advanced Update Support
firefox-0:128.6.0-1.el8_2
Fixed · RHSA-2025:0133
Red Hat Enterprise Linux 8.2 Advanced Update Support
thunderbird-0:128.6.0-3.el8_2
Fixed · RHSA-2025:0286
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
firefox-0:128.6.0-1.el8_4
Fixed · RHSA-2025:0134
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
thunderbird-0:128.6.0-3.el8_4
Fixed · RHSA-2025:0287
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
firefox-0:128.6.0-1.el8_4
Fixed · RHSA-2025:0134
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
thunderbird-0:128.6.0-3.el8_4
Fixed · RHSA-2025:0287
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
firefox-0:128.6.0-1.el8_4
Fixed · RHSA-2025:0134
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
thunderbird-0:128.6.0-3.el8_4
Fixed · RHSA-2025:0287
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
firefox-0:128.6.0-1.el8_6
Fixed · RHSA-2025:0136
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
thunderbird-0:128.6.0-3.el8_6
Fixed · RHSA-2025:0275
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
firefox-0:128.6.0-1.el8_6
Fixed · RHSA-2025:0136
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
thunderbird-0:128.6.0-3.el8_6
Fixed · RHSA-2025:0275
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
firefox-0:128.6.0-1.el8_6
Fixed · RHSA-2025:0136
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
thunderbird-0:128.6.0-3.el8_6
Fixed · RHSA-2025:0275
Red Hat Enterprise Linux 8.8 Extended Update Support
firefox-0:128.6.0-1.el8_8
Fixed · RHSA-2025:0137
Red Hat Enterprise Linux 8.8 Extended Update Support
thunderbird-0:128.6.0-3.el8_8
Fixed · RHSA-2025:0284
Red Hat Enterprise Linux 9
firefox-0:128.6.0-1.el9_5
Fixed · RHSA-2025:0080
Red Hat Enterprise Linux 9
thunderbird-0:128.6.0-3.el9_5
Fixed · RHSA-2025:0147
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
firefox-0:128.6.0-1.el9_0
Fixed · RHSA-2025:0162
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
thunderbird-0:128.6.0-3.el9_0
Fixed · RHSA-2025:0165
Red Hat Enterprise Linux 9.2 Extended Update Support
firefox-0:128.6.0-1.el9_2
Fixed · RHSA-2025:0138
Red Hat Enterprise Linux 9.2 Extended Update Support
thunderbird-0:128.6.0-3.el9_2
Fixed · RHSA-2025:0167
Red Hat Enterprise Linux 9.4 Extended Update Support
firefox-0:128.6.0-1.el9_4
Fixed · RHSA-2025:0135
Red Hat Enterprise Linux 9.4 Extended Update Support
thunderbird-0:128.6.0-3.el9_4
Fixed · RHSA-2025:0166
Red Hat Enterprise Linux 10
firefox
Affected
Red Hat Enterprise Linux 10
firefox-flatpak-container
Affected
Red Hat Enterprise Linux 10
thunderbird
Affected
Red Hat Enterprise Linux 10
thunderbird-flatpak-container
Affected
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
Red Hat Enterprise Linux 7
thunderbird
Out of support scope
Red Hat Enterprise Linux 9
firefox:flatpak/firefox
Affected
Red Hat Enterprise Linux 9
thunderbird:flatpak/thunderbird
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | firefox-0:128.6.0-1.el7_9 | Fixed | RHSA-2025:0132 |
| Red Hat Enterprise Linux 8 | firefox-0:128.6.0-1.el8_10 | Fixed | RHSA-2025:0144 |
| Red Hat Enterprise Linux 8 | thunderbird-0:128.6.0-3.el8_10 | Fixed | RHSA-2025:0281 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | firefox-0:128.6.0-1.el8_2 | Fixed | RHSA-2025:0133 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | thunderbird-0:128.6.0-3.el8_2 | Fixed | RHSA-2025:0286 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | firefox-0:128.6.0-1.el8_4 | Fixed | RHSA-2025:0134 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:128.6.0-3.el8_4 | Fixed | RHSA-2025:0287 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | firefox-0:128.6.0-1.el8_4 | Fixed | RHSA-2025:0134 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | thunderbird-0:128.6.0-3.el8_4 | Fixed | RHSA-2025:0287 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | firefox-0:128.6.0-1.el8_4 | Fixed | RHSA-2025:0134 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | thunderbird-0:128.6.0-3.el8_4 | Fixed | RHSA-2025:0287 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | firefox-0:128.6.0-1.el8_6 | Fixed | RHSA-2025:0136 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | thunderbird-0:128.6.0-3.el8_6 | Fixed | RHSA-2025:0275 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | firefox-0:128.6.0-1.el8_6 | Fixed | RHSA-2025:0136 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | thunderbird-0:128.6.0-3.el8_6 | Fixed | RHSA-2025:0275 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | firefox-0:128.6.0-1.el8_6 | Fixed | RHSA-2025:0136 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | thunderbird-0:128.6.0-3.el8_6 | Fixed | RHSA-2025:0275 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | firefox-0:128.6.0-1.el8_8 | Fixed | RHSA-2025:0137 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | thunderbird-0:128.6.0-3.el8_8 | Fixed | RHSA-2025:0284 |
| Red Hat Enterprise Linux 9 | firefox-0:128.6.0-1.el9_5 | Fixed | RHSA-2025:0080 |
| Red Hat Enterprise Linux 9 | thunderbird-0:128.6.0-3.el9_5 | Fixed | RHSA-2025:0147 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | firefox-0:128.6.0-1.el9_0 | Fixed | RHSA-2025:0162 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | thunderbird-0:128.6.0-3.el9_0 | Fixed | RHSA-2025:0165 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | firefox-0:128.6.0-1.el9_2 | Fixed | RHSA-2025:0138 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | thunderbird-0:128.6.0-3.el9_2 | Fixed | RHSA-2025:0167 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | firefox-0:128.6.0-1.el9_4 | Fixed | RHSA-2025:0135 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | thunderbird-0:128.6.0-3.el9_4 | Fixed | RHSA-2025:0166 |
| Red Hat Enterprise Linux 10 | firefox | Affected | n/a |
| Red Hat Enterprise Linux 10 | firefox-flatpak-container | Affected | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Affected | n/a |
| Red Hat Enterprise Linux 10 | thunderbird-flatpak-container | Affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | firefox:flatpak/firefox | Affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird:flatpak/thunderbird | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
References (10)
- https://access.redhat.com/security/cve/CVE-2025-0243 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1827142%2C1932783 Broken LinkIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2336175 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-0243
- https://www.cve.org/CVERecord?id=CVE-2025-0243
- https://www.mozilla.org/security/advisories/mfsa2025-01/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-02/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-04/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2025-05/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-0243 | Vendor Advisory | |
| https://bugzilla.mozilla.org/buglist.cgi?bug_id=1827142%2C1932783 | Broken LinkIssue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2336175 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-0243 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-0243 | ||
| https://www.mozilla.org/security/advisories/mfsa2025-01/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2025-02/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2025-04/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2025-05/ | Vendor Advisory |
Change history (0)
No recorded changes yet.