[ALSA-2026:19370] Important: firefox security update
Type:
security
Severity:
important
Release date:
2026-05-26
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1 (CVE-2026-7323) * firefox: thunderbird: Information disclosure due to incorrect boundary conditions in the Audio/Video component (CVE-2026-7320) * firefox: thunderbird: Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1 (CVE-2026-7322) * firefox: thunderbird: webrtc: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component (CVE-2026-7321) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 firefox-140.10.1-1.el9_8.alma.1.aarch64.rpm 87b7ab7b9cf2bc34973a8ba5f27f48a0ebf80287af05745c7ac154b532367046
aarch64 firefox-x11-140.10.1-1.el9_8.alma.1.aarch64.rpm 9340b225cf172e71719d2d26d0a6c52d0645eb24e52f552d75bbc5d5e1fa5cbb
ppc64le firefox-x11-140.10.1-1.el9_8.alma.1.ppc64le.rpm 9a9e009dc0595c1d762b2dcdbee001cd4dacbacf04c93c0e69b4af6a44d0922b
ppc64le firefox-140.10.1-1.el9_8.alma.1.ppc64le.rpm ab69ff35ec2e9c0ccf7b29f4c2405bd2ed3880582a82e9c8b6ba62bdb3e05d92
s390x firefox-x11-140.10.1-1.el9_8.alma.1.s390x.rpm e0b1d356ab2bdbd5f413657593f88a37ad4f4317d94fbabe649b2a82517fcca4
s390x firefox-140.10.1-1.el9_8.alma.1.s390x.rpm e9421ee93632abffa62616bcdf121ea092f6695189fdfbe3a06ef5d00b90cda2
x86_64 firefox-140.10.1-1.el9_8.alma.1.x86_64.rpm 06266333ea3ce57b290f5589407d1ed299565c6cbe740cbb9179c39c945d0909
x86_64 firefox-x11-140.10.1-1.el9_8.alma.1.x86_64.rpm 89fcde9002f9007bdcbcfb10b5eb2de8e1260fac9b3146722492b8cd440f2f2c
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.