PT-2025-4125 · Mozilla+10 · Thunderbird+12

Nils Bars

·

Published

2025-02-04

·

Updated

2025-07-22

·

CVE-2025-1012

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 135 Firefox ESR versions prior to 115.20 Firefox ESR versions prior to 128.7 Thunderbird versions prior to 128.7 Thunderbird versions prior to 135
Description A race during concurrent delazification could have led to a use-after-free. This issue affects several versions of Firefox and Thunderbird.
Recommendations For Firefox versions prior to 135, update to version 135 or later. For Firefox ESR versions prior to 115.20, update to version 115.20 or later. For Firefox ESR versions prior to 128.7, update to version 128.7 or later. For Thunderbird versions prior to 128.7, update to version 128.7 or later. For Thunderbird versions prior to 135, update to version 135 or later.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2025:1066
ALSA-2025:1184
ALSA-2025:1283
ALSA-2025:1292
ALT-PU-2025-2842
ALT-PU-2025-3108
ALT-PU-2025-3294
ALT-PU-2025-4001
ALT-PU-2025-7695
ALT-PU-2025-7697
BDU:2025-02312
CESA-2025_1283
CESA-2025_1292
CVE-2025-1012
DLA-4044-1
DLA-4045-1
DSA-5858-1
DSA-5861-1
INFSA-2025_1066
INFSA-2025_1184
INFSA-2025_1283
INFSA-2025_1292
MGASA-2025-0045
MGASA-2025-0048
OESA-2025-1101
OESA-2025-1102
OESA-2025-1835
OPENSUSE-SU-2025:14727-1
OPENSUSE-SU-2025:14730-1
OPENSUSE-SU-2025:14731-1
OPENSUSE-SU-2025_0374-1
OPENSUSE-SU-2025_0405-1
RHSA-2025:1066
RHSA-2025:1132
RHSA-2025:1133
RHSA-2025:1135
RHSA-2025:1136
RHSA-2025:1137
RHSA-2025:1138
RHSA-2025:1139
RHSA-2025:1140
RHSA-2025:1184
RHSA-2025:1283
RHSA-2025:1292
RHSA-2025:1317
RHSA-2025:1318
RHSA-2025:1319
RHSA-2025:1339
RHSA-2025:1340
RHSA-2025:1341
RHSA-2025:1348
RHSA-2025_1066
RHSA-2025_1184
RHSA-2025_1283
RHSA-2025_1292
RLSA-2025:1283
RLSA-2025:1292
SUSE-SU-2025:0374-1
SUSE-SU-2025:0391-1
SUSE-SU-2025:0405-1
SUSE-SU-2025_0374-1
SUSE-SU-2025_0391-1
USN-7263-1
USN-7663-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu