CVE-2025-9179

NameCVE-2025-9179
DescriptionAn attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4277-1, DLA-4279-1, DSA-5980-1, DSA-5984-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
firefox (PTS)sid142.0.1-1fixed
firefox-esr (PTS)bullseye115.14.0esr-1~deb11u1vulnerable
bullseye (security)128.14.0esr-1~deb11u1fixed
bookworm, bookworm (security)128.14.0esr-1~deb12u1fixed
trixie (security), trixie128.14.0esr-1~deb13u1fixed
forky, sid128.14.0esr-1fixed
thunderbird (PTS)bullseye1:115.12.0-1~deb11u1vulnerable
bullseye (security)1:128.14.0esr-1~deb11u1fixed
bookworm, bookworm (security)1:128.14.0esr-1~deb12u1fixed
trixie (security), trixie1:128.14.0esr-1~deb13u1fixed
forky, sid1:128.14.0esr-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firefoxsource(unstable)142.0-1
firefox-esrsourcebullseye128.14.0esr-1~deb11u1DLA-4277-1
firefox-esrsourcebookworm128.14.0esr-1~deb12u1DSA-5980-1
firefox-esrsourcetrixie128.14.0esr-1~deb13u1DSA-5980-1
firefox-esrsource(unstable)128.14.0esr-1
thunderbirdsourcebullseye1:128.14.0esr-1~deb11u1DLA-4279-1
thunderbirdsourcebookworm1:128.14.0esr-1~deb12u1DSA-5984-1
thunderbirdsourcetrixie1:128.14.0esr-1~deb13u1DSA-5984-1
thunderbirdsource(unstable)1:128.14.0esr-1

Notes

https://www.mozilla.org/en-US/security/advisories/mfsa2025-66/#CVE-2025-9179
https://www.mozilla.org/en-US/security/advisories/mfsa2025-64/#CVE-2025-9179
https://www.mozilla.org/en-US/security/advisories/mfsa2025-71/#CVE-2025-9179

Search for package or bug name: Reporting problems