Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Security Fix(es):
* libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416)
* libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636)
* thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (CVE-2026-5734)
* thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (CVE-2026-5731)
* firefox: thunderbird: Incorrect boundary conditions, integer overflow in the Graphics: Text component (CVE-2026-5732)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
firefox-x11-140.9.1-1.el9_7.alma.1.aarch64.rpm |
1e7cf05d4494b227cd76a03f44f700ceb39fd8ab78ffac46d2776373ade28423 |
| aarch64 |
firefox-140.9.1-1.el9_7.alma.1.aarch64.rpm |
4583935e3b53c1b2537cda6ce312e5975861e2e5c172017d01e93cd395f65c2d |
| ppc64le |
firefox-x11-140.9.1-1.el9_7.alma.1.ppc64le.rpm |
2d808d4ee7c3f29dd978909248377b41a8fbac81c170b3777efae7ec83dfeadb |
| ppc64le |
firefox-140.9.1-1.el9_7.alma.1.ppc64le.rpm |
b6fb96a0a138c27f7814c596e8fdd5144d998b04de50207dd5c915cef2b1af9f |
| s390x |
firefox-x11-140.9.1-1.el9_7.alma.1.s390x.rpm |
2c49998846d970973a3455280811a863f29025bfd941406c926158d5468313bf |
| s390x |
firefox-140.9.1-1.el9_7.alma.1.s390x.rpm |
f4e14d639792fb985a32ad155091f740be836e3aa7eefa5ededf19a080cb4852 |
| x86_64 |
firefox-140.9.1-1.el9_7.alma.1.x86_64.rpm |
3897467ff56fe0fc886dfe90512c8cb361baffd9f8390ea7269ebc26e56a2f1f |
| x86_64 |
firefox-x11-140.9.1-1.el9_7.alma.1.x86_64.rpm |
5b125030d7d7a76e913e172275e5a3e336304d06bbed99b8a9ab93bacd7fae84 |