Amazon Linux 2 Security Advisory: ALAS2-2025-3008
Advisory Released Date: 2025-09-29
Advisory Updated Date: 2025-09-29
FAQs regarding Amazon Linux ALAS/CVE Severity
Sandbox escape due to use-after-free in the Graphics: Canvas2D component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10527)
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10528)
Same-origin policy bypass in the Layout component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10529)
Incorrect boundary conditions in the JavaScript: GC component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10532)
Integer overflow in the SVG component.
This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10533)
Information disclosure in the Networking: Cache component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10536)
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10537)
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. (CVE-2025-59375)
Affected Packages:
thunderbird
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update thunderbird or yum update --advisory ALAS2-2025-3008 to update your system.
aarch64:
thunderbird-140.3.0-1.amzn2.0.1.aarch64
src:
thunderbird-140.3.0-1.amzn2.0.1.src
x86_64:
thunderbird-140.3.0-1.amzn2.0.1.x86_64