[ALSA-2025:23034] Important: firefox security update
Type:
security
Severity:
important
Release date:
2025-12-12
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146 (CVE-2025-14333) * firefox: Use-after-free in the WebRTC: Signaling component (CVE-2025-14321) * firefox: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2025-14325) * firefox: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2025-14322) * firefox: Privilege escalation in the Netmonitor component (CVE-2025-14328) * firefox: Privilege escalation in the Netmonitor component (CVE-2025-14329) * firefox: Same-origin policy bypass in the Request Handling component (CVE-2025-14331) * firefox: Privilege escalation in the DOM: Notifications component (CVE-2025-14323) * firefox: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2025-14330) * firefox: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2025-14324) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 firefox-140.6.0-1.el9_7.alma.1.aarch64.rpm 0e548bf2822210981be6789042198090730f6d3e149658835b8f34182bf23278
aarch64 firefox-x11-140.6.0-1.el9_7.alma.1.aarch64.rpm 35858db4d731ee3c70e3972eba84acdf355e45cdf680e6aa612be5dc05770c69
ppc64le firefox-140.6.0-1.el9_7.alma.1.ppc64le.rpm a103ec5b02efa8a61519b74972f7cf120f419c4d2549cc2128dfcbb3371df5c4
ppc64le firefox-x11-140.6.0-1.el9_7.alma.1.ppc64le.rpm e13ee6d3e6560e99cdfecf0fc6cc467668b016f883f142ffd6c1ed0cef00cd41
s390x firefox-140.6.0-1.el9_7.alma.1.s390x.rpm 3756e3cd2834f4abb4ab1b345b40832fcd21082371c5e4ecf3215f6f9011559b
s390x firefox-x11-140.6.0-1.el9_7.alma.1.s390x.rpm 967084870f398dc3defa2f6a6b0ce155670feb273ff80a5890a86418d28e5c49
x86_64 firefox-x11-140.6.0-1.el9_7.alma.1.x86_64.rpm 49056cd5c7a2094fd40cb1a8f693656cc11783693a672a753f9c6ce4fc8e1994
x86_64 firefox-140.6.0-1.el9_7.alma.1.x86_64.rpm e2df165ca77fd0475b5ea95fb0b2a40c22ddad641d9a47c22ef7d9a053c58961
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.