[ALSA-2026:69461] Important: firefox security update
Type:
security
Severity:
important
Release date:
2026-09-25
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024) * firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019) * firefox: thunderbird: Use-after-free in the Networking component (CVE-2026-92026) * firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-92031) * firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component (CVE-2026-92032) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92010) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92006) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92011) * firefox: thunderbird: Use-after-free in the DOM: Streams component (CVE-2026-92027) * firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-92028) * firefox: thunderbird: Privilege escalation in the WebExtensions component (CVE-2026-92015) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92013) * firefox: thunderbird: Use-after-free in the Disability Access APIs component (CVE-2026-92016) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92012) * firefox: thunderbird: Use-after-free in the DOM: HTML Parser component (CVE-2026-92022) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component (CVE-2026-92014) * firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component (CVE-2026-92018) * firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component (CVE-2026-92021) * firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component (CVE-2026-92005) * firefox: thunderbird: Privilege escalation in the DOM: Service Workers component (CVE-2026-92017) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92009) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component (CVE-2026-92020) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92008) * firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component (CVE-2026-92030) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92007) * firefox: thunderbird: Use-after-free in the DOM: Navigation component (CVE-2026-92025) * firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92029) * firefox: thunderbird: Use-after-free in the XML component (CVE-2026-92023) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 firefox-140.16.0-1.el10_2.aarch64.rpm b661ccb7beb361bc8aa843b5c23e73c0e7399b8951fdfe4fc914315db212a82f
ppc64le firefox-140.16.0-1.el10_2.ppc64le.rpm 1ab410ce1eb3fd70ed6195c0e441be7014baf0388ba52d2f28923e213f9d371f
s390x firefox-140.16.0-1.el10_2.s390x.rpm cc3b2c3d679ae15c643da70e7b8184c5302af0c3bb5b87612264c83b6d6eab15
x86_64 firefox-140.16.0-1.el10_2.x86_64.rpm 82655c4f97cbb3524fac7dc82a822a3af8d5e7b6ac6d49fe8960d81491cad5fc
x86_64_v2 firefox-140.16.0-1.el10_2.x86_64_v2.rpm 857dfab6ab70dce4126890065c7fe823b41ccca811f168c769b83cb444f9b93c
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.