Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Security Fix(es):
* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)
* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)
* firefox: thunderbird: Use-after-free in the Networking component (CVE-2026-92026)
* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-92031)
* firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component (CVE-2026-92032)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92010)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92006)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92011)
* firefox: thunderbird: Use-after-free in the DOM: Streams component (CVE-2026-92027)
* firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-92028)
* firefox: thunderbird: Privilege escalation in the WebExtensions component (CVE-2026-92015)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92013)
* firefox: thunderbird: Use-after-free in the Disability Access APIs component (CVE-2026-92016)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92012)
* firefox: thunderbird: Use-after-free in the DOM: HTML Parser component (CVE-2026-92022)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component (CVE-2026-92014)
* firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component (CVE-2026-92018)
* firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component (CVE-2026-92021)
* firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component (CVE-2026-92005)
* firefox: thunderbird: Privilege escalation in the DOM: Service Workers component (CVE-2026-92017)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92009)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component (CVE-2026-92020)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92008)
* firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component (CVE-2026-92030)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92007)
* firefox: thunderbird: Use-after-free in the DOM: Navigation component (CVE-2026-92025)
* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92029)
* firefox: thunderbird: Use-after-free in the XML component (CVE-2026-92023)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
firefox-140.16.0-1.el9_8.alma.1.aarch64.rpm |
a50ebd2405b1b244441eaae56353ae14de792d698d2c22496cd55ffafb57cff3 |
| aarch64 |
firefox-x11-140.16.0-1.el9_8.alma.1.aarch64.rpm |
f0b6cca3584b70fda856fb399df561bde2b85d2898e431f47ffe8a06a90e33c8 |
| ppc64le |
firefox-140.16.0-1.el9_8.alma.1.ppc64le.rpm |
af7abcb2f4133c27121cfeb44519a7e73203036bd575d5d69486cd581095f9fb |
| ppc64le |
firefox-x11-140.16.0-1.el9_8.alma.1.ppc64le.rpm |
e045fb9f0bd6b2e67aaa7fa7d38e90ef75e7cc5368cdb5c5108094444cff995a |
| s390x |
firefox-140.16.0-1.el9_8.alma.1.s390x.rpm |
86df861c4a66d109781b8ef337e890f71888befe7b978c0d893ce3448454d772 |
| s390x |
firefox-x11-140.16.0-1.el9_8.alma.1.s390x.rpm |
fbf008b6507ddb41eafd6169d861318a533529ca5c4e763a27090efaac1d68e4 |
| x86_64 |
firefox-140.16.0-1.el9_8.alma.1.x86_64.rpm |
2a0faedc7748d06abf524401c7d4e77ef995b5136c8f817afa9414c80c92b500 |
| x86_64 |
firefox-x11-140.16.0-1.el9_8.alma.1.x86_64.rpm |
beb23797ddbd24deef9289113f7332e27976ed985d416dc6ce254f9d270d7e15 |