CVE-2025-5262: Double Free
A double-free could have occurred in vpxcodecencinitmulti after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
Other sources
A double-free could have occurred in vpxcodecencinitmulti after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5262?
CVE-2025-5262 is considered a high severity vulnerability due to the potential for memory corruption and crashes.
How do I fix CVE-2025-5262?
To fix CVE-2025-5262, upgrade to Firefox version 139 or Firefox ESR versions 115.24 or 128.11.
Which versions of Firefox are affected by CVE-2025-5262?
CVE-2025-5262 affects Firefox versions prior to 139 and Firefox ESR versions prior to 115.24 and 128.11.
Is there a risk of exploitation with CVE-2025-5262?
Yes, CVE-2025-5262 could lead to a potentially exploitable crash due to the conditions outlined in the vulnerability.
What type of vulnerability is CVE-2025-5262?
CVE-2025-5262 is a double-free vulnerability occurring during the initialization of the WebRTC encoder.