CVE-2025-6430
Advisory
ALSA-2025:10072
Important: firefox security update
ecosystem: alma:9Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: Content-Disposition header ignored when a file is included in an embed or object tag (CVE-2025-6430) * firefox: Use-after-free in FontFaceSet (CVE-2025-6424) * firefox: Incorrect parsing of URLs could have allowed embedding of youtube.com (CVE-2025-6429) * firefox: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID (CVE-2025-6425) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References
- errata.almalinux.org: https://access.redhat.com/errata/RHSA-2025:10072
- errata.almalinux.org: https://access.redhat.com/security/cve/CVE-2025-6424
- errata.almalinux.org: https://access.redhat.com/security/cve/CVE-2025-6425
- errata.almalinux.org: https://access.redhat.com/security/cve/CVE-2025-6429
- errata.almalinux.org: https://access.redhat.com/security/cve/CVE-2025-6430
- errata.almalinux.org: https://bugzilla.redhat.com/2374555
- errata.almalinux.org: https://bugzilla.redhat.com/2374559
- errata.almalinux.org: https://bugzilla.redhat.com/2374561
- errata.almalinux.org: https://bugzilla.redhat.com/2374562
- errata.almalinux.org: https://errata.almalinux.org/9/ALSA-2025-10072.html
published: 2025-07-01 00:00:00
modified: 2025-07-01 19:40:59
Vulnerability
CVE-2025-6430
CVE-2025-6430
ecosystem: alma:9References
- errata.almalinux.org: https://access.redhat.com/security/cve/CVE-2025-6430
Detection
OR
rpm
firefox
package type: binary
Architectures
- aarch64
- ppc64le
- s390x
- x86_64
Affected version range
less than
0:128.12.0-1.el9_6.alma.1
fixed
0:128.12.0-1.el9_6.alma.1
rpm
firefox-x11
package type: binary
Architectures
- aarch64
- ppc64le
- s390x
- x86_64
Affected version range
less than
0:128.12.0-1.el9_6.alma.1
fixed
0:128.12.0-1.el9_6.alma.1
Data Sources
- AlmaLinux Errata
alma-errata