Description:
Use-after-free in the WebRTC: Signaling component. (CVE-2025-14321)
Sandbox escape due to incorrect boundary conditions in the Graphics:
CanvasWebGL component. (CVE-2025-14322)
Privilege escalation in the DOM: Notifications component.
(CVE-2025-14323)
JIT miscompilation in the JavaScript Engine: JIT component.
(CVE-2025-14324, CVE-2025-14325, CVE-2025-14330)
Privilege escalation in the Netmonitor component. (CVE-2025-14328,
CVE-2025-14329)
Same-origin policy bypass in the Request Handling component.
(CVE-2025-14331)
Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6,
Firefox 146 and Thunderbird 146. (CVE-2025-14333)
- https://bugs.mageia.org/show_bug.cgi?id=34814
- https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/-FCacePkmj8
- https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/V7GVSScpn5w
- https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/qFuz87KunGc
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_118.html
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_118_1.html
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_119.html
- https://www.firefox.com/en-US/firefox/140.6.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-94/
- https://www.cve.org/CVERecord?id=CVE-2025-14321
- https://www.cve.org/CVERecord?id=CVE-2025-14322
- https://www.cve.org/CVERecord?id=CVE-2025-14323
- https://www.cve.org/CVERecord?id=CVE-2025-14324
- https://www.cve.org/CVERecord?id=CVE-2025-14325
- https://www.cve.org/CVERecord?id=CVE-2025-14328
- https://www.cve.org/CVERecord?id=CVE-2025-14329
- https://www.cve.org/CVERecord?id=CVE-2025-14330
- https://www.cve.org/CVERecord?id=CVE-2025-14331
- https://www.cve.org/CVERecord?id=CVE-2025-14333
- 9/core/nspr-4.38.2-1.mga9
- 9/core/nss-3.119.0-1.mga9
- 9/core/firefox-140.6.0-1.mga9
- 9/core/firefox-l10n-140.6.0-1.mga9
Get the latest Linux and open source security news straight to your inbox.