CVE-2025-1932

high
Published 2025-03-05 Β· Modified 2026-06-04
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability was fixed in Firefox 136, Firefox ESR 128.8, Thunderbird 136, and Thunderbird 128.8.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access Red Hat statement Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. CVSS v3: 8.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7 Extended Lifecycle…

Description

firefox: Inconsistent comparator in XSLT sorting led to out-of-bounds access

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

CVSS v3: 8.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7 Extended Lifecycle Supportfirefox-0:128.8.0-1.el7_9RHSA-2025:26992025-03-13T00:00:00Z
Red Hat Enterprise Linux 8firefox-0:128.8.0-1.el8_10RHSA-2025:24522025-03-06T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportfirefox-0:128.8.0-1.el8_2RHSA-2025:27082025-03-13T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportfirefox-0:128.8.0-1.el8_4RHSA-2025:24842025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicefirefox-0:128.8.0-1.el8_4RHSA-2025:24842025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionsfirefox-0:128.8.0-1.el8_4RHSA-2025:24842025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportfirefox-0:128.8.0-1.el8_6RHSA-2025:24852025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicefirefox-0:128.8.0-1.el8_6RHSA-2025:24852025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsfirefox-0:128.8.0-1.el8_6RHSA-2025:24852025-03-10T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supportfirefox-0:128.8.0-1.el8_8RHSA-2025:24862025-03-10T00:00:00Z
Red Hat Enterprise Linux 9firefox-0:128.8.0-1.el9_5RHSA-2025:23592025-03-05T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsfirefox-0:128.8.0-1.el9_0RHSA-2025:24812025-03-10T00:00:00Z
Red Hat Enterprise Linux 9.2 Extended Update Supportfirefox-0:128.8.0-1.el9_2RHSA-2025:24802025-03-10T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportfirefox-0:128.8.0-1.el9_4RHSA-2025:24792025-03-10T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10firefoxAffected
Red Hat Enterprise Linux 10firefox-flatpak-containerAffected
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 9firefox-flatpak-containerAffected

Apply commands

bash fix
Apply RHSA-2025:2699 for Red Hat Enterprise Linux 7 Extended Lifecycle Support
yum update -y firefox
# or:
dnf upgrade -y firefox

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 9Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 128.8.0esr-1
sid Fixed 136.0-1
forky Fixed 128.8.0esr-1
bullseye Fixed 128.8.0esr-1~deb11u1
bookworm Fixed 128.8.0esr-1~deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.