FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- use-after-free after failed memory allocation

Affected packages
firefox < 134.0,2
librewolf < 134.0
firefox-esr < 128.6.0
thunderbird < 128.6

Details

VuXML ID ee407762-116c-11f0-8b2c-b42e991fc52e
Discovery 2025-01-07
Entry 2025-04-04

security@mozilla.org reports:

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash.

References

CVE Name CVE-2025-0238
URL https://nvd.nist.gov/vuln/detail/CVE-2025-0238