Amazon Linux 2023 Security Advisory: ALAS2023-2025-1203
Advisory Released Date: 2025-09-29
Advisory Updated Date: 2025-09-29
FAQs regarding Amazon Linux ALAS/CVE Severity
Sandbox escape due to use-after-free in the Graphics: Canvas2D component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10527)
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10528)
Same-origin policy bypass in the Layout component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10529)
Incorrect boundary conditions in the JavaScript: GC component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10532)
Integer overflow in the SVG component.
This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10533)
Information disclosure in the Networking: Cache component.
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10536)
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. (CVE-2025-10537)
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. (CVE-2025-59375)
Affected Packages:
firefox
Issue Correction:
Run dnf update firefox --releasever 2023.9.20250929 or dnf update --advisory ALAS2023-2025-1203 --releasever 2023.9.20250929 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
firefox-debuginfo-140.3.0-1.amzn2023.0.1.aarch64
firefox-140.3.0-1.amzn2023.0.1.aarch64
firefox-debugsource-140.3.0-1.amzn2023.0.1.aarch64
src:
firefox-140.3.0-1.amzn2023.0.1.src
x86_64:
firefox-debuginfo-140.3.0-1.amzn2023.0.1.x86_64
firefox-140.3.0-1.amzn2023.0.1.x86_64
firefox-debugsource-140.3.0-1.amzn2023.0.1.x86_64