Change History (8)
comment:1 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 11 months ago
comment:3 by , 11 months ago
I was wrong about security information. There are fixes, I'll prepare the information soon.
comment:4 by , 11 months ago
| Severity: | normal → critical |
|---|
Security fixes
Level: Critical
- Low: 1
- Moderate: 5
- High: 11
- Critical: 1
- CVE-2025-5263 (Moderate): Error handling for script execution was incorrectly isolated from web content
- CVE-2025-5264 (Moderate): Potential local code execution in “Copy as cURL” command
- CVE-2025-5265 (Moderate): Potential local code execution in “Copy as cURL” command
- CVE-2025-5283 (Critical): Double-free in libvpx encoder
- CVE-2025-6424 (High): Use-after-free in FontFaceSet
- CVE-2025-6425 (Moderate): The WebCompat WebExtension shipped with Firefox exposed a persistent UUID
- CVE-2025-8027 (High): JavaScript engine only wrote partial return value to stack
- CVE-2025-8028 (High): Large branch table could lead to truncated instruction
- CVE-2025-8033 (Low): Incorrect JavaScript state machine for generators
- CVE-2025-8034 (High): Memory safety bugs
- CVE-2025-9179 (High): Sandbox escape due to invalid pointer in the Audio/Video: GMP component
- CVE-2025-9180 (High): Same-origin policy bypass in the Graphics: Canvas2D component
- CVE-2025-9185 (High): Memory safety bugs
- CVE-2025-10533 (Moderate): Integer overflow in the SVG component
- CVE-2025-11709 (High): Out of bounds read/write in a privileged process triggered by WebGL textures
- CVE-2025-11710 (High): Cross-process information leaked due to malicious IPC messages
- CVE-2025-11711 (High): Some non-writable Object properties could be modified
- CVE-2025-11714 (High): Memory safety bugs.
comment:5 by , 11 months ago
| Priority: | normal → high |
|---|
comment:6 by , 11 months ago
Fixed at 2973645cb6234dd489b79d660d859b151f441076. Keeping open for SA issuing.
Note:
See TracTickets
for help on using tickets.

Changes
As far as I can tell from the security information, checking the SM repositories, and how they keep up to date with a given major.minor of Firefox and Thunderbird, there isn't any security fixes with this release.