Unrated severityNVD Advisory· Published May 27, 2025· Updated Aug 25, 2025
CVE-2025-5262
CVE-2025-5262
Description
A double-free could have occurred in vpx_codec_enc_init_multi after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
Affected products
8- osv-coords7 versionspkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP6pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7
< 128.11.0-1.1+ 6 more
- (no CPE)range: < 128.11.0-1.1
- (no CPE)range: < 128.11.0-150200.8.221.1
- (no CPE)range: < 128.11.0-1.1
- (no CPE)range: < 128.11.0-150200.8.221.1
- (no CPE)range: < 128.11.0-150200.8.221.1
- (no CPE)range: < 128.11.0-150200.8.221.1
- (no CPE)range: < 128.11.0-150200.8.221.1
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.