Home

Description

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

PUBLISHED Reserved 2025-07-22 | Published 2025-07-22 | Updated 2026-04-13 | Assigner mozilla

Product status

115.26 (rpm)
unaffected

128.13 (rpm)
unaffected

140.1 (rpm)
unaffected

141 (rpm)
unaffected

128.13 (rpm)
unaffected

140.1 (rpm)
unaffected

141 (rpm)
unaffected

Credits

Gary Kwong

References

lists.debian.org/debian-lts-announce/2025/07/msg00016.html

bugzilla.mozilla.org/show_bug.cgi?id=1971581

www.mozilla.org/security/advisories/mfsa2025-56/

www.mozilla.org/security/advisories/mfsa2025-57/

www.mozilla.org/security/advisories/mfsa2025-58/

www.mozilla.org/security/advisories/mfsa2025-59/

www.mozilla.org/security/advisories/mfsa2025-61/

www.mozilla.org/security/advisories/mfsa2025-62/

www.mozilla.org/security/advisories/mfsa2025-63/

cve.org (CVE-2025-8028)

nvd.nist.gov (CVE-2025-8028)

Download JSON