CVE-2025-8027 Information

Description

On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT however read the entire 64 bits. This vulnerability affects Firefox < 141 Firefox ESR < 115.26 Firefox ESR < 128.13 Firefox ESR < 140.1 Thunderbird < 141 Thunderbird < 128.13 and Thunderbird < 140.1.

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1968423 https://www.mozilla.org/security/advisories/mfsa2025-56/ https://www.mozilla.org/security/advisories/mfsa2025-57/ https://www.mozilla.org/security/advisories/mfsa2025-58/ https://www.mozilla.org/security/advisories/mfsa2025-59/ https://www.mozilla.org/security/advisories/mfsa2025-61/ https://www.mozilla.org/security/advisories/mfsa2025-62/ https://www.mozilla.org/security/advisories/mfsa2025-63/

CNNVD-202507-2922 (Published: 2025-07-22)

Share on: