CVE-2025-1932

high
Published 2025-03-05 · Modified 2025-03-06
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
8.0

Description

RHSA-2025:2452: firefox security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access Red Hat statement Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. CVSS v3: 8.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7 Extended Lifecycle…

Description

firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

CVSS v3: 8.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7 Extended Lifecycle Supportfirefox-0:128.8.0-1.el7_9RHSA-2025:26992025-03-13T00:00:00Z
Red Hat Enterprise Linux 8firefox-0:128.8.0-1.el8_10RHSA-2025:24522025-03-06T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportfirefox-0:128.8.0-1.el8_2RHSA-2025:27082025-03-13T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportfirefox-0:128.8.0-1.el8_4RHSA-2025:24842025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicefirefox-0:128.8.0-1.el8_4RHSA-2025:24842025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionsfirefox-0:128.8.0-1.el8_4RHSA-2025:24842025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportfirefox-0:128.8.0-1.el8_6RHSA-2025:24852025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicefirefox-0:128.8.0-1.el8_6RHSA-2025:24852025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsfirefox-0:128.8.0-1.el8_6RHSA-2025:24852025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supportfirefox-0:128.8.0-1.el8_8RHSA-2025:24862025-03-10T00:00:00Z
Red Hat Enterprise Linux 9firefox-0:128.8.0-1.el9_5RHSA-2025:23592025-03-05T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsfirefox-0:128.8.0-1.el9_0RHSA-2025:24812025-03-10T00:00:00Z
Red Hat Enterprise Linux 9.2 Extended Update Supportfirefox-0:128.8.0-1.el9_2RHSA-2025:24802025-03-10T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportfirefox-0:128.8.0-1.el9_4RHSA-2025:24792025-03-10T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10firefoxAffected
Red Hat Enterprise Linux 10firefox-flatpak-containerAffected
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 9firefox-flatpak-containerAffected

Apply commands

bash fix
Apply RHSA-2025:2699 for Red Hat Enterprise Linux 7 Extended Lifecycle Support
yum update -y firefox
# or:
dnf upgrade -y firefox

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 9Affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
debian debiansidfixed136.0-1
debian debianbookwormfixed128.8.0esr-1~deb12u1
debian debianbullseyefixed128.8.0esr-1~deb11u1
debian debianforkyfixed128.8.0esr-1
debian debiantrixiefixed128.8.0esr-1
suse slesaffected
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.