Updated rootcerts, nss & firefox packages fix security vulnerabilities
Publication date: 27 May 2025Modification date: 27 May 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4918 , CVE-2025-4919
Description
Out-of-bounds access when resolving Promise objects. (CVE-2025-4918) Out-of-bounds access when optimizing linear sums. (CVE-2025-4919)
References
- https://bugs.mageia.org/show_bug.cgi?id=34287
- https://www.mozilla.org/en-US/firefox/128.10.1/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2025-37/
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_111.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4918
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-4919
SRPMS
9/core
- rootcerts-20250424.00-1.mga9
- nss-3.111.0-1.mga9
- firefox-128.10.1-2.mga9
- firefox-l10n-128.10.1-1.mga9