CVE-2025-14330
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-14330 is a JIT miscompilation vulnerability in the JavaScript Engine's JIT component of Mozilla Firefox and Thunderbird, affecting the RISC-V 64-bit (riscv64) platform specifically. The flaw was discovered by Rong Bao and disclosed on December 9, 2025, affecting Firefox before version 146, Firefox ESR before 140.6, Thunderbird before 146, and Thunderbird ESR before 140.6. Mozilla rated the impact as moderate in its advisories, though Feedly's CVSS v3.1 estimate assigns a base score of 9.8 (Critical) — this discrepancy reflects that the vulnerability is constrained to a tier-3 (RISC-V) platform not officially shipped by Mozilla (Mozilla Advisory Firefox 146, Mozilla Advisory ESR 140.6).

Technical details

The root cause is an incorrect argument passed to the ExtractBits function within unboxGCThingForGCBarrier in the RISC-V 64-bit JIT backend: the function was called with JSVAL_TAG_SHIFT - 1 instead of the correct JSVAL_TAG_SHIFT as the bit-size parameter, causing the JIT compiler to generate incorrect machine code for GC barrier pre-barrier fast paths (CWE-686: Function Call With Incorrect Argument Type; CWE-843: Type Confusion; CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer). This miscompilation leads to intermittent SIGSEGV crashes when JIT-compiled code attempts to read from an invalid memory address during garbage collection barrier execution on the riscv64 simulator. The bug was introduced by a regression from Bug 1800431 and was reproducible by running a crafted JavaScript file in a riscv64 JS shell build, producing a segfault in approximately 4 out of 15 consecutive runs (Mozilla Bugzilla).

Impact

Successful exploitation could cause a crash (denial of service) in Firefox or Thunderbird on RISC-V 64-bit platforms due to the invalid memory read in JIT-compiled code. Because the flaw involves memory mishandling in the JIT engine, there is a theoretical risk of memory corruption that could potentially be leveraged for arbitrary code execution, though Mozilla assessed the practical exploitability as moderate given the tier-3 platform constraint. The vulnerability is scoped exclusively to riscv64 builds and does not affect x86, x86-64, ARM, or other officially Mozilla-shipped platforms (Mozilla Advisory Firefox 146, Mozilla Bugzilla).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for CVE-2025-14330. The vulnerability is limited to the RISC-V 64-bit (tier-3) platform, which significantly reduces the attack surface since Mozilla does not officially ship Firefox binaries for riscv64. The EPSS score is 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Mozilla Bugzilla, Mozilla Advisory ESR 140.6).

Mitigation and workarounds

Mozilla has released patches addressing this vulnerability in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird ESR 140.6, all announced December 9, 2025. Users and administrators running Firefox or Thunderbird on RISC-V 64-bit platforms should upgrade to these fixed versions immediately. The specific fix corrects the ExtractBits call in unboxGCThingForGCBarrier to use JSVAL_TAG_SHIFT instead of JSVAL_TAG_SHIFT - 1, and was backported to the ESR 140 branch (Mozilla Advisory Firefox 146, Mozilla Advisory ESR 140.6, Mozilla Bugzilla).

Community reactions

Mozilla classified this vulnerability as moderate impact in its official security advisories, noting it is constrained to the RISC-V 64-bit tier-3 platform. The bug was submitted for Mozilla's security bounty program but was declined because RISC-V is not an officially Mozilla-shipped platform and the reporter had contributed to the relevant codebase. The vulnerability received standard downstream patching coverage from Red Hat, Debian, Oracle Linux, Rocky Linux, AlmaLinux, SUSE, and Amazon Linux, indicating routine security update propagation without significant community alarm (Mozilla Bugzilla, Mozilla Advisory Firefox 146).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

thunderbird: 1:140.6.0esr-1~deb12u1

Fixed

sid

thunderbird: 1:140.6.0esr-1

Fixed

trixie

thunderbird: 1:140.6.0esr-1~deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-apps)

mozjs38

Unknown

devel

firefox

Not Affected

jammy

thunderbird: 1:140.7.1+build1-0ubuntu0.22.04.1

Fixed

noble

firefox

Not Affected

questing

firefox

Not Affected

resolute

firefox

Not Affected

RHEL / CentOS

Fixed

RHEL 8

:appstream:firefox-0:140.6.0-1.el8_10.src

Fixed

RHEL 9

:appstream:firefox-0:140.6.0-1.el9_0.src

Fixed

RHEL 10

firefox-0:140.6.0-1.el10_0.src

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management