Opened 11 months ago

Closed 10 months ago

Last modified 8 months ago

#22369 closed enhancement (fixed)

firefox-140.5.0esr (and spidermonkey)

Reported by: Joe Locash Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Release notes not available yet.

Attachments (1)

firefox-jsonschema.patch​ (1.8 KB ) - added by Zhang Wen 11 months ago.

Download all attachments as: .zip

Change History (13)

comment:1 by zeckma, 11 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by Xi Ruoyao, 11 months ago

Summary: firefox-140.5.0esr → firefox-140.5.0esr (and spidermonkey)

spidermonkey seems ok. I'm unsure if there's any security updates for that.

comment:3 by Joe Locash, 11 months ago

Priority: normal → high

Security fixes: ​https://www.mozilla.org/en-US/security/advisories/mfsa2025-88/

  • MFSA-RESERVE-2025-1991458: Race condition in the Graphics component (high)
  • MFSA-RESERVE-2025-1992130: Incorrect boundary conditions in the JavaScript: WebAssembly component (high)
  • MFSA-RESERVE-2025-1980904: Same-origin policy bypass in the DOM: Notifications component (moderate)
  • MFSA-RESERVE-2025-1984940: Mitigation bypass in the DOM: Security component (moderate)
  • MFSA-RESERVE-2025-1988412: Same-origin policy bypass in the DOM: Workers component (moderate)
  • MFSA-RESERVE-2025-1991945: Mitigation bypass in the DOM: Core & HTML component (moderate)
  • MFSA-RESERVE-2025-1995686: Use-after-free in the WebRTC: Audio/Video component (moderate)
  • MFSA-RESERVE-2025-1994241: Use-after-free in the Audio/Video component (moderate)
  • MFSA-RESERVE-2025-1994164: Spoofing issue in Firefox (low)

comment:4 by Douglas R. Reno, 11 months ago

CVEs are now available for the vulnerabilities (and Spidermonkey will need an advisory for CVE-2025-13016)

comment:5 by zeckma, 11 months ago

CVEs for easier SA filing (same as Thunderbird)

  • Rating: High
  • Total: 9; High: 2; Moderate: 6; Low: 1
  • CVE-2025-13012 (High): Race condition in the Graphics component
  • CVE-2025-13016 (High): Incorrect boundary conditions in the JavaScript: WebAssembly component
  • CVE-2025-13017 (Moderate): Same-origin policy bypass in the DOM: Notifications component
  • CVE-2025-13018 (Moderate): Mitigation bypass in the DOM: Security component
  • CVE-2025-13019 (Moderate): Same-origin policy bypass in the DOM: Workers component
  • CVE-2025-13013 (Moderate): Mitigation bypass in the DOM: Core & HTML component
  • CVE-2025-13020 (Moderate): Use-after-free in the WebRTC: Audio/Video component
  • CVE-2025-13014 (Moderate): Use-after-free in the Audio/Video component
  • CVE-2025-13015 (Low): Spoofing issue in Firefox

by Zhang Wen, 11 months ago

Attachment: firefox-jsonschema.patch​ added

comment:6 by Zhang Wen, 11 months ago

On my machine the third party component jsonschema need to be patch to build firefox-140.5.0 properly

comment:7 by zeckma, 11 months ago

I'll see if I can reproduce it in a bit!

in reply to:  6 ; comment:8 by Xi Ruoyao, 11 months ago

Replying to Zhang Wen:

On my machine the third party component jsonschema need to be patch to build firefox-140.5.0 properly

Already mentioned in #22244 (comment 2). It seems strange they've applied two of the patches but not the third one though.

in reply to:  8 comment:9 by Zhang Wen, 11 months ago

Replying to Xi Ruoyao:

Already mentioned in #22244 (comment 2). It seems strange they've applied two of the patches but not the third one though.

In the third patch it reads:

# jsonschema 4.17.3 is incompatible with Python 3.14+,but later versions use a dependency with Rust components, which we thus can't vendor. For now we apply the minimal patch to jsonschema to make it work again.

I guess they're waiting for a more regular solution instead of a tricky patch, but not for sure.

comment:10 by zeckma, 11 months ago

Fixed at 5e542c862f120f2ad5d249b006cb6c424e5b6558. Leaving open for SA issuing, I'll handle it.

comment:11 by zeckma, 10 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-045 and SA-12.4-046 issued.

comment:12 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.