MFSA-TMP-2025-0001: Critical severity firefox esr vulnerability
A double-free could have occurred in vpxcodecencinitmulti after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of MFSA-TMP-2025-0001?
MFSA-TMP-2025-0001 is classified as a moderate severity vulnerability due to potential memory corruption.
How do I fix MFSA-TMP-2025-0001?
To fix MFSA-TMP-2025-0001, update Firefox ESR to version 128.11 or 115.24, or upgrade to Firefox version 139.
What issues could result from MFSA-TMP-2025-0001?
MFSA-TMP-2025-0001 could lead to memory corruption and potentially exploit a crash in affected applications.
Which versions of Firefox are affected by MFSA-TMP-2025-0001?
Affected versions include Firefox ESR versions up to 128.11 and 115.24, and Firefox up to version 139.
What is the cause of MFSA-TMP-2025-0001?
MFSA-TMP-2025-0001 is caused by a double-free issue occurring in vpx_codec_enc_init_multi during encoder initialization in WebRTC.