Bug 2395759 (CVE-2025-10537) - CVE-2025-10537 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143
Summary: CVE-2025-10537 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR ...
Keywords:
Status: NEW
Alias: CVE-2025-10537
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-09-16 13:02 UTC by OSIDB Bzimport
Modified: 2025-10-07 09:42 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:16108 0 None None None 2025-09-17 15:47:42 UTC
Red Hat Product Errata RHSA-2025:16109 0 None None None 2025-09-17 15:38:49 UTC
Red Hat Product Errata RHSA-2025:16156 0 None None None 2025-09-18 10:23:00 UTC
Red Hat Product Errata RHSA-2025:16157 0 None None None 2025-09-18 13:08:32 UTC
Red Hat Product Errata RHSA-2025:16260 0 None None None 2025-09-22 01:23:20 UTC
Red Hat Product Errata RHSA-2025:16589 0 None None None 2025-09-24 14:05:06 UTC
Red Hat Product Errata RHSA-2025:17340 0 None None None 2025-10-06 01:29:20 UTC
Red Hat Product Errata RHSA-2025:17341 0 None None None 2025-10-06 01:28:09 UTC
Red Hat Product Errata RHSA-2025:17342 0 None None None 2025-10-06 01:30:28 UTC
Red Hat Product Errata RHSA-2025:17343 0 None None None 2025-10-06 01:34:42 UTC
Red Hat Product Errata RHSA-2025:17344 0 None None None 2025-10-06 01:34:27 UTC
Red Hat Product Errata RHSA-2025:17345 0 None None None 2025-10-06 01:36:32 UTC
Red Hat Product Errata RHSA-2025:17346 0 None None None 2025-10-06 02:28:16 UTC
Red Hat Product Errata RHSA-2025:17367 0 None None None 2025-10-06 09:04:11 UTC
Red Hat Product Errata RHSA-2025:17368 0 None None None 2025-10-06 09:03:47 UTC
Red Hat Product Errata RHSA-2025:17371 0 None None None 2025-10-06 09:34:45 UTC
Red Hat Product Errata RHSA-2025:17372 0 None None None 2025-10-06 09:33:09 UTC
Red Hat Product Errata RHSA-2025:17373 0 None None None 2025-10-06 09:42:11 UTC
Red Hat Product Errata RHSA-2025:17374 0 None None None 2025-10-06 10:03:16 UTC
Red Hat Product Errata RHSA-2025:17378 0 None None None 2025-10-06 11:49:20 UTC
Red Hat Product Errata RHSA-2025:17453 0 None None None 2025-10-07 09:42:42 UTC

Description OSIDB Bzimport 2025-09-16 13:02:22 UTC
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143 and Firefox ESR < 140.3.

Comment 1 errata-xmlrpc 2025-09-17 15:38:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:16109 https://access.redhat.com/errata/RHSA-2025:16109

Comment 2 errata-xmlrpc 2025-09-17 15:47:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:16108 https://access.redhat.com/errata/RHSA-2025:16108

Comment 3 errata-xmlrpc 2025-09-18 10:22:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:16156 https://access.redhat.com/errata/RHSA-2025:16156

Comment 4 errata-xmlrpc 2025-09-18 13:08:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:16157 https://access.redhat.com/errata/RHSA-2025:16157

Comment 5 errata-xmlrpc 2025-09-22 01:23:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:16260 https://access.redhat.com/errata/RHSA-2025:16260

Comment 7 errata-xmlrpc 2025-09-24 14:05:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:16589 https://access.redhat.com/errata/RHSA-2025:16589

Comment 8 errata-xmlrpc 2025-10-06 01:28:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2025:17341 https://access.redhat.com/errata/RHSA-2025:17341

Comment 9 errata-xmlrpc 2025-10-06 01:29:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:17340 https://access.redhat.com/errata/RHSA-2025:17340

Comment 10 errata-xmlrpc 2025-10-06 01:30:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:17342 https://access.redhat.com/errata/RHSA-2025:17342

Comment 11 errata-xmlrpc 2025-10-06 01:34:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:17344 https://access.redhat.com/errata/RHSA-2025:17344

Comment 12 errata-xmlrpc 2025-10-06 01:34:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:17343 https://access.redhat.com/errata/RHSA-2025:17343

Comment 13 errata-xmlrpc 2025-10-06 01:36:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:17345 https://access.redhat.com/errata/RHSA-2025:17345

Comment 14 errata-xmlrpc 2025-10-06 02:28:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:17346 https://access.redhat.com/errata/RHSA-2025:17346

Comment 15 errata-xmlrpc 2025-10-06 09:03:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:17368 https://access.redhat.com/errata/RHSA-2025:17368

Comment 16 errata-xmlrpc 2025-10-06 09:04:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:17367 https://access.redhat.com/errata/RHSA-2025:17367

Comment 17 errata-xmlrpc 2025-10-06 09:33:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:17372 https://access.redhat.com/errata/RHSA-2025:17372

Comment 18 errata-xmlrpc 2025-10-06 09:34:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2025:17371 https://access.redhat.com/errata/RHSA-2025:17371

Comment 19 errata-xmlrpc 2025-10-06 09:42:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:17373 https://access.redhat.com/errata/RHSA-2025:17373

Comment 20 errata-xmlrpc 2025-10-06 10:03:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:17374 https://access.redhat.com/errata/RHSA-2025:17374

Comment 21 errata-xmlrpc 2025-10-06 11:49:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:17378 https://access.redhat.com/errata/RHSA-2025:17378

Comment 22 errata-xmlrpc 2025-10-07 09:42:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:17453 https://access.redhat.com/errata/RHSA-2025:17453


Note You need to log in before you can comment on or make changes to this bug.