Red Hat Security Advisory: firefox security update
Red Hat has issued a security advisory for Firefox addressing two vulnerabilities involving out-of-bounds access in Firefox and Thunderbird. These vulnerabilities are identified as CVE-2025-4918 and CVE-2025-4919. The issues relate to out-of-bounds access when resolving Promise objects and when optimizing linear sums. The advisory rates the security impact as Important and provides updated Firefox packages for Red Hat Enterprise Linux 8.4. No CVSS score is provided in the advisory.
AI Analysis
Technical Summary
This Red Hat security advisory addresses two vulnerabilities in Mozilla Firefox and Thunderbird, both involving out-of-bounds access errors (CWE-787). CVE-2025-4918 concerns out-of-bounds access during Promise object resolution, while CVE-2025-4919 involves out-of-bounds access during optimization of linear sums. These vulnerabilities could potentially lead to memory corruption or crashes. The advisory provides updated Firefox packages for Red Hat Enterprise Linux 8.4 to remediate these issues. No CVSS score is included in the advisory, but the impact is rated as Important by Red Hat Product Security.
Potential Impact
The vulnerabilities involve out-of-bounds memory access, which can lead to memory corruption, crashes, or potentially other undefined behavior in Firefox and Thunderbird. The advisory classifies the security impact as Important, indicating a significant risk but does not provide further details on exploitation or impact severity. There are no known exploits in the wild at the time of the advisory.
Mitigation Recommendations
Red Hat has released updated Firefox packages for Red Hat Enterprise Linux 8.4 that address these vulnerabilities. Users should apply the provided security updates to remediate the issues. For detailed update instructions, refer to the Red Hat article at https://access.redhat.com/articles/11258. No additional mitigation actions are specified or required beyond applying the official patches.
Red Hat Security Advisory: firefox security update
Description
Red Hat has issued a security advisory for Firefox addressing two vulnerabilities involving out-of-bounds access in Firefox and Thunderbird. These vulnerabilities are identified as CVE-2025-4918 and CVE-2025-4919. The issues relate to out-of-bounds access when resolving Promise objects and when optimizing linear sums. The advisory rates the security impact as Important and provides updated Firefox packages for Red Hat Enterprise Linux 8.4. No CVSS score is provided in the advisory.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory addresses two vulnerabilities in Mozilla Firefox and Thunderbird, both involving out-of-bounds access errors (CWE-787). CVE-2025-4918 concerns out-of-bounds access during Promise object resolution, while CVE-2025-4919 involves out-of-bounds access during optimization of linear sums. These vulnerabilities could potentially lead to memory corruption or crashes. The advisory provides updated Firefox packages for Red Hat Enterprise Linux 8.4 to remediate these issues. No CVSS score is included in the advisory, but the impact is rated as Important by Red Hat Product Security.
Potential Impact
The vulnerabilities involve out-of-bounds memory access, which can lead to memory corruption, crashes, or potentially other undefined behavior in Firefox and Thunderbird. The advisory classifies the security impact as Important, indicating a significant risk but does not provide further details on exploitation or impact severity. There are no known exploits in the wild at the time of the advisory.
Mitigation Recommendations
Red Hat has released updated Firefox packages for Red Hat Enterprise Linux 8.4 that address these vulnerabilities. Users should apply the provided security updates to remediate the issues. For detailed update instructions, refer to the Red Hat article at https://access.redhat.com/articles/11258. No additional mitigation actions are specified or required beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:8640
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-4919"]
Threat ID: 6a4049e227e9c797198330ad
Added to database: 06/27/2026, 22:08:34 UTC
Last enriched: 06/27/2026, 22:29:54 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.