[ALSA-2026:7671] Important: firefox security update
Type:
security
Severity:
important
Release date:
2026-04-15
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416) * libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636) * thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (CVE-2026-5734) * thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (CVE-2026-5731) * firefox: thunderbird: Incorrect boundary conditions, integer overflow in the Graphics: Text component (CVE-2026-5732) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 firefox-x11-140.9.1-1.el9_7.alma.1.aarch64.rpm 1e7cf05d4494b227cd76a03f44f700ceb39fd8ab78ffac46d2776373ade28423
aarch64 firefox-140.9.1-1.el9_7.alma.1.aarch64.rpm 4583935e3b53c1b2537cda6ce312e5975861e2e5c172017d01e93cd395f65c2d
ppc64le firefox-x11-140.9.1-1.el9_7.alma.1.ppc64le.rpm 2d808d4ee7c3f29dd978909248377b41a8fbac81c170b3777efae7ec83dfeadb
ppc64le firefox-140.9.1-1.el9_7.alma.1.ppc64le.rpm b6fb96a0a138c27f7814c596e8fdd5144d998b04de50207dd5c915cef2b1af9f
s390x firefox-x11-140.9.1-1.el9_7.alma.1.s390x.rpm 2c49998846d970973a3455280811a863f29025bfd941406c926158d5468313bf
s390x firefox-140.9.1-1.el9_7.alma.1.s390x.rpm f4e14d639792fb985a32ad155091f740be836e3aa7eefa5ededf19a080cb4852
x86_64 firefox-140.9.1-1.el9_7.alma.1.x86_64.rpm 3897467ff56fe0fc886dfe90512c8cb361baffd9f8390ea7269ebc26e56a2f1f
x86_64 firefox-x11-140.9.1-1.el9_7.alma.1.x86_64.rpm 5b125030d7d7a76e913e172275e5a3e336304d06bbed99b8a9ab93bacd7fae84
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.