CVE-2025-3032

Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

13 Apr 2026, 15:16

Type Values Removed Values Added
Summary (en) Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137. (en) Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

07 Apr 2025, 13:31

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
First Time Mozilla firefox
Mozilla thunderbird
Mozilla
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1949987 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1949987 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-20/ - () https://www.mozilla.org/security/advisories/mfsa2025-20/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-23/ - () https://www.mozilla.org/security/advisories/mfsa2025-23/ - Vendor Advisory
Summary
  • (es) La filtración de descriptores de archivos del servidor de bifurcación a los procesos de contenido web podría permitir ataques de escalada de privilegios. Esta vulnerabilidad afecta a Firefox (versión anterior a la 137) y Thunderbird (versión anterior a la 137).

01 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4
CWE CWE-403

01 Apr 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 13:15

Updated : 2026-04-13 15:16


NVD link : CVE-2025-3032

Mitre link : CVE-2025-3032

CVE.ORG link : CVE-2025-3032


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-403

Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')