CVE-2025-8040: Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.1 - Upgrade
Upgrade
Mozilla Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 141
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8040?
CVE-2025-8040 has a high severity due to the potential for exploitation leading to arbitrary code execution.
How do I fix CVE-2025-8040?
To resolve CVE-2025-8040, upgrade to Firefox version 141 or Thunderbird version 140.1.
What products are affected by CVE-2025-8040?
CVE-2025-8040 affects Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140, and Thunderbird 140.
What types of bugs are present in CVE-2025-8040?
CVE-2025-8040 includes memory safety bugs that may lead to memory corruption.
Can CVE-2025-8040 be exploited remotely?
Yes, with sufficient effort, the memory corruption issues in CVE-2025-8040 could potentially be exploited to run arbitrary code.