CVE-2025-3032
published 2025-04-01CVE-2025-3032: Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox…
PriorityP344high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.38%
29.7th percentile
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 137.0-1 (sid) | firefox 137.0-1 (sid) |
| mozilla | firefox | < 137.0 | 137.0 |
| mozilla | firefox | — | — |
| mozilla | thunderbird | < 137.0 | 137.0 |
| mozilla | thunderbird | >= 0 < 1:140.7.1+build1-0ubuntu0.22.04.1 | 1:140.7.1+build1-0ubuntu0.22.04.1 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_redhat7.8HIGH
vendor_debian7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
kernel: ipv6: reject malicious packets in ipv6_gso_segment()
vendor_redhat·2025-08-19·CVSS 7.8
CVE-2025-38572 [HIGH] CWE-120 kernel: ipv6: reject malicious packets in ipv6_gso_segment()
kernel: ipv6: reject malicious packets in ipv6_gso_segment()
In the Linux kernel, the following vulnerability has been resolved:
ipv6: reject malicious packets in ipv6_gso_segment()
syzbot was able to craft a packet with very long IPv6 extension headers
leading to an overflow of skb->transport_header.
This 16bit field has a limited range.
Add skb_reset_transport_header_careful() helper and use it
from ipv6_gso_segment()
WARNING: CPU: 0 PID: 5871 at ./include/linux/skbuff.h:3032 skb_reset_transport_header include/linux/skbuff.h:3032 [inline]
WARNING: CPU: 0 PID: 5871 at ./include/linux/skbuff.h:3032 ipv6_gso_segment+0x15e2/0x21e0 net/ipv6/ip6_offload.c:151
Modules linked in:
CPU: 0 UID: 0 PID: 5871 Comm: syz-executor211 Not tainted 6.16.0-rc6-syzkaller-g7abc678e3084 #0 PREEMPT(full)
Hardwa
Red Hat
thunderbird: firefox: Leaking file descriptors from the fork server
vendor_redhat·2025-04-01·CVSS 7.4
CVE-2025-3032 [HIGH] CWE-497 thunderbird: firefox: Leaking file descriptors from the fork server
thunderbird: firefox: Leaking file descriptors from the fork server
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Fix deferred
Package: firefox-flatpak-container (Red Hat Enterprise Linux 10) - Fix deferred
Package: thunderbird (Red Hat Enterprise Linux 10)
Debian
CVE-2025-3032: firefox - Leaking of file descriptors from the fork server to web content processes could ...
vendor_debian·2025·CVSS 7.4
CVE-2025-3032 [HIGH] CVE-2025-3032: firefox - Leaking of file descriptors from the fork server to web content processes could ...
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.
Scope: local
sid: resolved (fixed in 137.0-1)
Mozilla
Mozilla Foundation Security Advisory 2025-20: CVE-2025-3032
vendor_mozilla·CVSS 7.4
CVE-2025-3032 [HIGH] Mozilla Foundation Security Advisory 2025-20: CVE-2025-3032
Mozilla Foundation Security Advisory 2025-20
CVE: CVE-2025-3032
Product: Firefox
Impact: high
Fixed in: Firefox 137
Mozilla
Mozilla Foundation Security Advisory 2025-23: CVE-2025-3032
vendor_mozilla·CVSS 7.4
CVE-2025-3032 [HIGH] Mozilla Foundation Security Advisory 2025-23: CVE-2025-3032
Mozilla Foundation Security Advisory 2025-23
CVE: CVE-2025-3032
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 137
GHSA
GHSA-h3xj-xc3c-cvpm: Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks
ghsa_unreviewed·2025-04-01
CVE-2025-3032 [HIGH] CWE-403 GHSA-h3xj-xc3c-cvpm: Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.
OSV
CVE-2025-3032: Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks
osv·2025-04-01·CVSS 7.4
CVE-2025-3032 [HIGH] CVE-2025-3032: Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.
No detection rules found.
No public exploits indexed.
2025-04-01
Published