RLSA-2026:47101

Source
https://errata.rockylinux.org/RLSA-2026:47101
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:47101.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2026:47101
Upstream
  • CVE-2026-15718
  • CVE-2026-15719
  • CVE-2026-16349
  • CVE-2026-16350
  • CVE-2026-16351
  • CVE-2026-16352
  • CVE-2026-16353
  • CVE-2026-16354
  • CVE-2026-16355
  • CVE-2026-16356
  • CVE-2026-16357
  • CVE-2026-16358
  • CVE-2026-16359
  • CVE-2026-16360
  • CVE-2026-16361
  • CVE-2026-16362
  • CVE-2026-16363
  • CVE-2026-16368
  • CVE-2026-16369
  • CVE-2026-16371
  • CVE-2026-16374
  • CVE-2026-16375
  • CVE-2026-16377
  • CVE-2026-16379
  • CVE-2026-16381
  • CVE-2026-16383
  • CVE-2026-16387
  • CVE-2026-16390
  • CVE-2026-16391
  • CVE-2026-16396
  • CVE-2026-16405
  • CVE-2026-16412
Published
2026-07-30T12:06:30.380063Z
Modified
2026-07-30T12:30:06.841874287Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Important: firefox security update
Details

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

  • firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719)

  • firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718)

  • firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390)

  • firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350)

  • firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391)

  • firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375)

  • firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356)

  • firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363)

  • firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412)

  • firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381)

  • firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355)

  • firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361)

  • firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352)

  • firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368)

  • firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377)

  • firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360)

  • firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362)

  • firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358)

  • firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387)

  • firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349)

  • firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357)

  • firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351)

  • firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371)

  • firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379)

  • firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354)

  • firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374)

  • firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359)

  • firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383)

  • firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369)

  • firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353)

  • firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396)

  • firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:10 / firefox

Package

Name
firefox
Purl
pkg:rpm/rocky-linux/firefox?distro=rocky-linux-10&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:140.13.0-1.el10_2
Database specific
{
    "yum_repository": "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:47101.json"