CVE-2025-1012: Use-after-free during concurrent delazification
A race during concurrent delazification could have led to a use-after-free.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 135.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 128.7.0esr-1~deb11u1Fixed in 128.7.0esr-1~deb12u1Fixed in 128.7.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:128.7.0esr-1~deb11u1Fixed in 1:128.7.0esr-1~deb12u1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128.7 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 135 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 128.7 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.20 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 135
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1012?
CVE-2025-1012 is classified as a critical vulnerability due to potential use-after-free conditions.
How do I fix CVE-2025-1012?
To fix CVE-2025-1012, update to the latest version of Firefox or Thunderbird as specified in the advisory.
Which software versions are affected by CVE-2025-1012?
CVE-2025-1012 affects Firefox versions below 135, Firefox ESR versions below 115.20, and Thunderbird versions below 135.
What kind of threat does CVE-2025-1012 pose?
CVE-2025-1012 poses a threat of exploitation through use-after-free vulnerabilities during concurrent operations.
Is CVE-2025-1012 currently being actively exploited?
At this time, there are no public reports indicating that CVE-2025-1012 is being actively exploited in the wild.