Attachments (1)
Change History (13)
comment:1 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 11 months ago
| Summary: | firefox-140.5.0esr → firefox-140.5.0esr (and spidermonkey) |
|---|
comment:3 by , 11 months ago
| Priority: | normal → high |
|---|
Security fixes: https://www.mozilla.org/en-US/security/advisories/mfsa2025-88/
- MFSA-RESERVE-2025-1991458: Race condition in the Graphics component (high)
- MFSA-RESERVE-2025-1992130: Incorrect boundary conditions in the JavaScript: WebAssembly component (high)
- MFSA-RESERVE-2025-1980904: Same-origin policy bypass in the DOM: Notifications component (moderate)
- MFSA-RESERVE-2025-1984940: Mitigation bypass in the DOM: Security component (moderate)
- MFSA-RESERVE-2025-1988412: Same-origin policy bypass in the DOM: Workers component (moderate)
- MFSA-RESERVE-2025-1991945: Mitigation bypass in the DOM: Core & HTML component (moderate)
- MFSA-RESERVE-2025-1995686: Use-after-free in the WebRTC: Audio/Video component (moderate)
- MFSA-RESERVE-2025-1994241: Use-after-free in the Audio/Video component (moderate)
- MFSA-RESERVE-2025-1994164: Spoofing issue in Firefox (low)
comment:4 by , 11 months ago
CVEs are now available for the vulnerabilities (and Spidermonkey will need an advisory for CVE-2025-13016)
comment:5 by , 11 months ago
CVEs for easier SA filing (same as Thunderbird)
- Rating: High
- Total: 9; High: 2; Moderate: 6; Low: 1
- CVE-2025-13012 (High): Race condition in the Graphics component
- CVE-2025-13016 (High): Incorrect boundary conditions in the JavaScript: WebAssembly component
- CVE-2025-13017 (Moderate): Same-origin policy bypass in the DOM: Notifications component
- CVE-2025-13018 (Moderate): Mitigation bypass in the DOM: Security component
- CVE-2025-13019 (Moderate): Same-origin policy bypass in the DOM: Workers component
- CVE-2025-13013 (Moderate): Mitigation bypass in the DOM: Core & HTML component
- CVE-2025-13020 (Moderate): Use-after-free in the WebRTC: Audio/Video component
- CVE-2025-13014 (Moderate): Use-after-free in the Audio/Video component
- CVE-2025-13015 (Low): Spoofing issue in Firefox
by , 11 months ago
| Attachment: | firefox-jsonschema.patch added |
|---|
follow-up: 8 comment:6 by , 11 months ago
On my machine the third party component jsonschema need to be patch to build firefox-140.5.0 properly
follow-up: 9 comment:8 by , 11 months ago
comment:9 by , 11 months ago
Replying to Xi Ruoyao:
Already mentioned in #22244 (comment 2). It seems strange they've applied two of the patches but not the third one though.
In the third patch it reads:
# jsonschema 4.17.3 is incompatible with Python 3.14+,but later versions use a dependency with Rust components, which we thus can't vendor. For now we apply the minimal patch to jsonschema to make it work again.
I guess they're waiting for a more regular solution instead of a tricky patch, but not for sure.
comment:10 by , 11 months ago
Fixed at 5e542c862f120f2ad5d249b006cb6c424e5b6558. Leaving open for SA issuing, I'll handle it.
comment:11 by , 10 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
SA-12.4-045 and SA-12.4-046 issued.

spidermonkey seems ok. I'm unsure if there's any security updates for that.