Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Security Fix(es):
* libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode (CVE-2026-56208)
* firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719)
* firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718)
* firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390)
* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350)
* firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391)
* firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375)
* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356)
* firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412)
* firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381)
* firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361)
* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352)
* firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368)
* firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377)
* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360)
* firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362)
* firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358)
* firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387)
* firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349)
* firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357)
* firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351)
* firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371)
* firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379)
* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354)
* firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374)
* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359)
* firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383)
* firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369)
* firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353)
* firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396)
* firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
firefox-x11-140.13.0-1.el9_8.alma.1.aarch64.rpm |
14f8bb05999a998026975ae1273ced3e9fae8ea2ebf29bf76b373ae1e197eab7 |
| aarch64 |
firefox-140.13.0-1.el9_8.alma.1.aarch64.rpm |
f1c8db35e3fe847aceca903084d6a6ce355fe0bb1ba24df03746ef6b46a960f8 |
| ppc64le |
firefox-x11-140.13.0-1.el9_8.alma.1.ppc64le.rpm |
db0760d12e686d6a0223d76b925465596096686b5b42fd9295b8a2cf253e761f |
| ppc64le |
firefox-140.13.0-1.el9_8.alma.1.ppc64le.rpm |
dde8681eae36f07427798024c7c7c4afc4d301fa80a8136eae2187784a6f33ab |
| s390x |
firefox-140.13.0-1.el9_8.alma.1.s390x.rpm |
2856f7a4344d9832ad8c9ef4610da9bdb6458784118d3c6b4e984fd1c729ccce |
| s390x |
firefox-x11-140.13.0-1.el9_8.alma.1.s390x.rpm |
924de0c9cea06ec0e60b655182b0ae48d6b7e057ae31dc502f2cbedc9ae838f2 |
| x86_64 |
firefox-x11-140.13.0-1.el9_8.alma.1.x86_64.rpm |
5d3fab53d3bcc0b372f4dcd2d72e925510b950d04fc382bfa67258cf882dc2cf |
| x86_64 |
firefox-140.13.0-1.el9_8.alma.1.x86_64.rpm |
ecf07bb7811ac65344e30ced2941ad55f3f95c995750537468e7c3e29c193eb3 |