Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Security Fix(es):
* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)
* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)
* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)
* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)
* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)
* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)
* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)
* firefox: Use-after-free in the DOM: Core & HTML component (CVE-2026-84124)
* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)
* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
firefox-140.15.0-1.el8_10.alma.1.aarch64.rpm |
88dcdb4c4e1f6122d08725dca640ed52163acb9c04d5ac5d27f8792025636e15 |
| ppc64le |
firefox-140.15.0-1.el8_10.alma.1.ppc64le.rpm |
6c75a5f071276e369d3e1b21cb4723f897614024ba9464525384dbbc09994c1a |
| s390x |
firefox-140.15.0-1.el8_10.alma.1.s390x.rpm |
6c017c3d01cfd24f7488a6e8c91f748c161045defd527cb3143f3a363b45e9a5 |
| x86_64 |
firefox-140.15.0-1.el8_10.alma.1.x86_64.rpm |
2198d1ea24b433e1b5acf43464d0e6d66e86aeb8e7a511d60cd1a51a6a928a56 |