Issued at: 2024-10-25
    
    Updated at: 2024-10-25
  
 
  
    
      
        Synopsis
        Important: firefox security update
        
        Description
        
        
        Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
        
        
        
        Security Fix(es):
        
        
        
        * firefox: Use-after-free in Animation timeline (128.3.1 ESR Chemspill) (CVE-2024-9680)
        
        
        
        For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
        
        
        Affected products
        
          
          Rocky Linux 8 aarch64
          
          Rocky Linux 8 x86_64
          
        
         
        Fixes
        
          
          
            2317442
          
          
        
         
        CVEs
        
          
          
            
              CVE-2024-9680
            
          
          
        
       
     
    
      
        
Affected packages
        
        Rocky Linux 8 aarch64 - AppStream
        
          
          
            firefox-0:128.3.1-2.el8_10.aarch64.rpm
          
          
          
            firefox-0:128.3.1-2.el8_10.src.rpm
          
          
          
            firefox-debuginfo-0:128.3.1-2.el8_10.aarch64.rpm
          
          
          
            firefox-debugsource-0:128.3.1-2.el8_10.aarch64.rpm
          
          
          
        
        
        Rocky Linux 8 x86_64 - AppStream
        
          
          
            firefox-0:128.3.1-2.el8_10.src.rpm
          
          
          
            firefox-0:128.3.1-2.el8_10.x86_64.rpm
          
          
          
            firefox-debuginfo-0:128.3.1-2.el8_10.x86_64.rpm
          
          
          
            firefox-debugsource-0:128.3.1-2.el8_10.x86_64.rpm