RHSA-2025:10183: Important: firefox security update
Important: firefox security update
Other sources
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.Security Fix(es): firefox: Content-Disposition header ignored when a file is included in an embed or object tag (CVE-2025-6430) firefox: Use-after-free in FontFaceSet (CVE-2025-6424) firefox: Incorrect parsing of URLs could have allowed embedding of youtube.com (CVE-2025-6429) firefox: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID (CVE-2025-6425) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 128.12.0-1.el8_6 - Upgrade
Upgrade
redhat/firefox-debuginfoto a version that resolves this vulnerability.Fixed in 128.12.0-1.el8_6 - Upgrade
Upgrade
redhat/firefox-debugsourceto a version that resolves this vulnerability.Fixed in 128.12.0-1.el8_6 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 128.12.0-1.el8_6.aa - Upgrade
Upgrade
redhat/firefox-debuginfoto a version that resolves this vulnerability.Fixed in 128.12.0-1.el8_6.aa - Upgrade
Upgrade
redhat/firefox-debugsourceto a version that resolves this vulnerability.Fixed in 128.12.0-1.el8_6.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:10183?
The vulnerability RHSA-2025:10183 is classified as important due to its potential impact on security.
How do I fix RHSA-2025:10183?
To resolve RHSA-2025:10183, update to the patched version of Firefox, specifically 128.12.0-1.el8_6.
What systems are affected by RHSA-2025:10183?
RHSA-2025:10183 affects various versions of Red Hat Enterprise Linux that include the Firefox package.
What specific issue does RHSA-2025:10183 address?
RHSA-2025:10183 addresses an issue where the Content-Disposition header is ignored when a file is included in an embed or object tag.
Is there a workaround for RHSA-2025:10183?
There is no specific workaround for RHSA-2025:10183; it is recommended to apply the security update as soon as possible.