RHSA-2025:0132: Important: firefox security update
Important: firefox security update
Other sources
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.<br>Security Fix(es):<br><li> firefox: Use-after-free when breaking lines in text (CVE-2025-0238)</li> <li> firefox: Memory corruption when using JavaScript Text Segmentation (CVE-2025-0241)</li> <li> firefox: Alt-Svc ALPN validation failure when redirected (CVE-2025-0239)</li> <li> firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6 (CVE-2025-0243)</li> <li> firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6 (CVE-2025-0242)</li> <li> firefox: WebChannel APIs susceptible to confused deputy attack (CVE-2025-0237)</li> <li> firefox: Compartment mismatch when parsing JavaScript JSON module (CVE-2025-0240)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:0132?
The severity of RHSA-2025:0132 is classified as important due to memory corruption and use-after-free vulnerabilities in Mozilla Firefox.
How do I fix RHSA-2025:0132?
To fix RHSA-2025:0132, you should update your Firefox installation to version 128.6.0-1.el7_9 or a later version.
What vulnerabilities are addressed in RHSA-2025:0132?
RHSA-2025:0132 addresses two vulnerabilities: a use-after-free issue (CVE-2025-0238) and problems related to memory corruption.
Which systems are affected by RHSA-2025:0132?
RHSA-2025:0132 impacts Red Hat Enterprise Linux Server and its variants that use the specified Firefox version.
Is there a recommended version to upgrade to for RHSA-2025:0132?
For RHSA-2025:0132, it is recommended to upgrade to version 128.6.0-1.el7_9 of Firefox.