Bug 34232 - Firefox 128.10
Summary: Firefox 128.10
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-04-29 16:01 CEST by Nicolas Salguero
Modified: 2025-05-08 20:52 CEST (History)
7 users (show)

See Also:
Source RPM: firefox, firefox-l10n
CVE: CVE-2025-2817, CVE-2025-4083, CVE-2025-4087, CVE-2025-4091, CVE-2025-4093
Status comment:


Attachments

Description Nicolas Salguero 2025-04-29 16:01:13 CEST
Mozilla has released Firefox 128.10 on April 29:
https://www.mozilla.org/en-US/firefox/128.10.0/releasenotes/

Security issues fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2025-29/
Nicolas Salguero 2025-04-29 16:03:44 CEST

Whiteboard: (none) => MGA9TOO
Source RPM: (none) => firefox, firefox-l10n
CVE: (none) => CVE-2025-2817, CVE-2025-4083, CVE-2025-4087, CVE-2025-4091, CVE-2025-4093

Nicolas Salguero 2025-04-30 09:19:28 CEST

Assignee: bugsquad => nicolas.salguero

Comment 1 Morgan Leijström 2025-04-30 16:04:01 CEST
I see it built on mga9, and I start testing...

Status comment: (none) => Build failed on cauldron
CC: (none) => fri, nicolas.salguero

Morgan Leijström 2025-04-30 16:04:55 CEST

Assignee: nicolas.salguero => qa-bugs

Comment 2 katnatek 2025-05-01 04:24:00 CEST
(In reply to Morgan Leijström from comment #1)
> I see it built on mga9, and I start testing...

What is the hurry Nicholas always put the packages list + advisory
Comment 3 katnatek 2025-05-01 04:27:06 CEST
Packages list:

firefox-128.10.0-1.mga9
firefox-af-128.10.0-1.mga9
firefox-an-128.10.0-1.mga9
firefox-ar-128.10.0-1.mga9
firefox-ast-128.10.0-1.mga9
firefox-az-128.10.0-1.mga9
firefox-be-128.10.0-1.mga9
firefox-bg-128.10.0-1.mga9
firefox-bn-128.10.0-1.mga9
firefox-br-128.10.0-1.mga9
firefox-bs-128.10.0-1.mga9
firefox-ca-128.10.0-1.mga9
firefox-cs-128.10.0-1.mga9
firefox-cy-128.10.0-1.mga9
firefox-da-128.10.0-1.mga9
firefox-de-128.10.0-1.mga9
firefox-el-128.10.0-1.mga9
firefox-en_CA-128.10.0-1.mga9
firefox-en_GB-128.10.0-1.mga9
firefox-en_US-128.10.0-1.mga9
firefox-eo-128.10.0-1.mga9
firefox-es_AR-128.10.0-1.mga9
firefox-es_CL-128.10.0-1.mga9
firefox-es_ES-128.10.0-1.mga9
firefox-es_MX-128.10.0-1.mga9
firefox-et-128.10.0-1.mga9
firefox-eu-128.10.0-1.mga9
firefox-fa-128.10.0-1.mga9
firefox-ff-128.10.0-1.mga9
firefox-fi-128.10.0-1.mga9
firefox-fr-128.10.0-1.mga9
firefox-fur-128.10.0-1.mga9
firefox-fy_NL-128.10.0-1.mga9
firefox-ga_IE-128.10.0-1.mga9
firefox-gd-128.10.0-1.mga9
firefox-gl-128.10.0-1.mga9
firefox-gu_IN-128.10.0-1.mga9
firefox-he-128.10.0-1.mga9
firefox-hi_IN-128.10.0-1.mga9
firefox-hr-128.10.0-1.mga9
firefox-hsb-128.10.0-1.mga9
firefox-hu-128.10.0-1.mga9
firefox-hy_AM-128.10.0-1.mga9
firefox-ia-128.10.0-1.mga9
firefox-id-128.10.0-1.mga9
firefox-is-128.10.0-1.mga9
firefox-it-128.10.0-1.mga9
firefox-ja-128.10.0-1.mga9
firefox-ka-128.10.0-1.mga9
firefox-kab-128.10.0-1.mga9
firefox-kk-128.10.0-1.mga9
firefox-km-128.10.0-1.mga9
firefox-kn-128.10.0-1.mga9
firefox-ko-128.10.0-1.mga9
firefox-lij-128.10.0-1.mga9
firefox-lt-128.10.0-1.mga9
firefox-lv-128.10.0-1.mga9
firefox-mk-128.10.0-1.mga9
firefox-mr-128.10.0-1.mga9
firefox-ms-128.10.0-1.mga9
firefox-my-128.10.0-1.mga9
firefox-nb_NO-128.10.0-1.mga9
firefox-nl-128.10.0-1.mga9
firefox-nn_NO-128.10.0-1.mga9
firefox-oc-128.10.0-1.mga9
firefox-pa_IN-128.10.0-1.mga9
firefox-pl-128.10.0-1.mga9
firefox-pt_BR-128.10.0-1.mga9
firefox-pt_PT-128.10.0-1.mga9
firefox-ro-128.10.0-1.mga9
firefox-ru-128.10.0-1.mga9
firefox-sc-128.10.0-1.mga9
firefox-si-128.10.0-1.mga9
firefox-sk-128.10.0-1.mga9
firefox-sl-128.10.0-1.mga9
firefox-sq-128.10.0-1.mga9
firefox-sr-128.10.0-1.mga9
firefox-sv_SE-128.10.0-1.mga9
firefox-szl-128.10.0-1.mga9
firefox-ta-128.10.0-1.mga9
firefox-te-128.10.0-1.mga9
firefox-tg-128.10.0-1.mga9
firefox-th-128.10.0-1.mga9
firefox-tl-128.10.0-1.mga9
firefox-tr-128.10.0-1.mga9
firefox-uk-128.10.0-1.mga9
firefox-ur-128.10.0-1.mga9
firefox-uz-128.10.0-1.mga9
firefox-vi-128.10.0-1.mga9
firefox-xh-128.10.0-1.mga9
firefox-zh_CN-128.10.0-1.mga9
firefox-zh_TW-128.10.0-1.mga9

SRPMs:
firefox-128.10.0-1.mga9.src.rpm
firefox-l10n-128.10.0-1.mga9.src.rpm

Waiting for advisory
Comment 4 Morgan Leijström 2025-05-01 12:35:54 CEST
(In reply to katnatek from comment #2) 
> What is the hurry

Bug is set to security + major

So good to start using ASAP
Comment 5 katnatek 2025-05-01 18:27:12 CEST
CVE-2025-2817 is in Firefox updater, as we don't use that, should we include that cve in our advisory?
Comment 6 David Walser 2025-05-01 18:49:50 CEST
You can exclude that one.
katnatek 2025-05-01 19:03:03 CEST

Keywords: (none) => advisory

Comment 7 Morgan Leijström 2025-05-01 20:14:47 CEST
mga9-64 OK here

Plasma, X11, AMD GPU

Clean update
Swedish localisation
Open tabs remembered, settings kept
Banking, video sites, shops
Printing


$ inxi -SMCG
System:
  Host: svarten.tribun Kernel: 6.6.88-desktop-3.mga9 arch: x86_64 bits: 64
  Desktop: KDE Plasma v: 5.27.10 Distro: Mageia 9
Machine:
  Type: Desktop Mobo: ASRock model: P55 Pro serial: <superuser required>
    BIOS: American Megatrends v: P2.60 date: 08/20/2010
CPU:
  Info: quad core model: Intel Core i7 870 bits: 64 type: MT MCP cache:
    L2: 1024 KiB
  Speed (MHz): avg: 1205 min/max: 1200/2934 cores: 1: 1205 2: 1205 3: 1205
    4: 1205 5: 1205 6: 1205 7: 1205 8: 1205
Graphics:
  Device-1: Advanced Micro Devices [AMD/ATI] Navi 24 [Radeon RX 6400/6500
    XT/6500M] driver: amdgpu v: kernel
  Display: x11 server: X.org v: 1.21.1.8 with: Xwayland v: 22.1.9 driver: X:
    loaded: amdgpu,v4l dri: radeonsi gpu: amdgpu resolution: 3840x2160~60Hz
  API: EGL v: 1.5 drivers: kms_swrast,radeonsi,swrast
    platforms: gbm,x11,surfaceless,device
  API: OpenGL v: 4.6 vendor: amd mesa v: 25.0.4 renderer: AMD Radeon RX
    6400 (radeonsi navi24 LLVM 15.0.6 DRM 3.54 6.6.88-desktop-3.mga9)
Nicolas Salguero 2025-05-02 11:22:14 CEST

Status comment: Build failed on cauldron => (none)
Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9

Comment 8 Brian Rockwell 2025-05-03 19:43:48 CEST
MGA9-64, Cinnamon

Installed and ran for several hours across multiple websites.  No issues

Will test some more on another box.

CC: (none) => brtians1

Comment 9 Jose Manuel López 2025-05-03 19:48:38 CEST
Hi.

Installed in Mga9 Plasma x64. No issues for now.

Banks ok.
Youtube ok.
Audio and Video ok.
Digital Certificates ok
Spanish tanslation ok.
Addons ok.

Greetings!

CC: (none) => Joselp

Comment 10 Thomas Andrews 2025-05-04 21:38:52 CEST
MGA9-64 Plasma. No installation issues. Used for two days now, with several different websites, no issues to report.

CC: (none) => andrewsfarm

Comment 11 Herman Viaene 2025-05-05 10:48:02 CEST
MGA9-64 Plasma Wayland on Compaq H000SB.
No installation issues.

Normal usage, including this here. All OK.

CC: (none) => herman.viaene

Comment 12 Jose Manuel López 2025-05-07 10:47:23 CEST
Installed in Mga 9 X64 Plasma. 
No installation issues.

Banks ok
Youtube ok.
Certificates ok.
Addons and settings ok.
Audio and video ok.
Autofirma (spanish signature application) ok.

Some warnings in terminal:

[jose@Prox14Amd ~]$ firefox
ATTENTION: default value of option mesa_glthread overridden by environment.
[Parent 338767, Main Thread] WARNING: /usr/share/applications/kde-mimeapps.list contains a [Added Associations] group, but it is not permitted here.  Only the non-desktop-specific mimeapps.list file may add or remove associations.: 'glib warning', file /home/iurt/rpmbuild/BUILD/firefox-128.10.0/toolkit/xre/nsSigHandlers.cpp:187

(firefox:338767): GLib-GIO-WARNING **: 10:44:34.378: /usr/share/applications/kde-mimeapps.list contains a [Added Associations] group, but it is not permitted here.  Only the non-desktop-specific mimeapps.list file may add or remove associations.


Greetings!
Comment 13 Brian Rockwell 2025-05-07 19:41:43 CEST
MGA9-64, Xfce, Asus Laptop, AMD A6-9225 RADEON R4


The following 4 packages are going to be installed:

- firefox-128.10.0-1.mga9.x86_64
- firefox-en_CA-128.10.0-1.mga9.noarch
- firefox-en_GB-128.10.0-1.mga9.noarch
- firefox-en_US-128.10.0-1.mga9.noarch

299KB of additional disk space will be used.

===rebooted

email
websites
video work
Comment 14 Thomas Andrews 2025-05-08 17:51:35 CEST
No issues with several tests. Validating.

CC: (none) => sysadmin-bugs
Whiteboard: (none) => MGA9-64-OK
Keywords: (none) => validated_update

Comment 15 Mageia Robot 2025-05-08 20:52:37 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0150.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.