[Apollo] Advisories Statistics light light Login

RLSA-2026:21380

Security Mirrored from RHSA-2026:21380
Issued at: 2026-06-04
Updated at: 2026-06-04

Synopsis

Important: firefox security update



Description

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

* firefox: Incorrect boundary conditions in the JavaScript Engine: JIT component (CVE-2026-8388)

* firefox: Other issue in the JavaScript Engine component (CVE-2026-8391)

* firefox: Sandbox escape in the Profile Backup component (CVE-2026-8401)

* firefox: Integer overflow in the Networking: JAR component (CVE-2026-8956)

* firefox: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 (CVE-2026-8975)

* firefox: Privilege escalation in the DOM: Workers component (CVE-2026-8955)

* firefox: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component (CVE-2026-8968)

* firefox: Incorrect boundary conditions, integer overflow in the Audio/Video component (CVE-2026-8954)

* firefox: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-8958)

* firefox: Incorrect boundary conditions in the Audio/Video: Web Codecs component (CVE-2026-8946)

* firefox: Privilege escalation in the Security component (CVE-2026-8970)

* firefox: Same-origin policy bypass in the Networking: HTTP component (CVE-2026-8950)

* firefox: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 (CVE-2026-8974)

* firefox: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-8953)

* firefox: Spoofing issue in the Form Autofill component (CVE-2026-8961)

* firefox: Use-after-free in the DOM: Bindings (WebIDL) component (CVE-2026-8947)

* firefox: Mitigation bypass in the DOM: Security component (CVE-2026-8962)

* firefox: Privilege escalation in the Enterprise Policies component (CVE-2026-8957)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 10 aarch64 Rocky Linux 10 ppc64le Rocky Linux 10 riscv64 Rocky Linux 10 s390x Rocky Linux 10 x86_64

Fixes

2479873 2479876 2479842 2476469 2479846 2479871 2479853 2479839 2476475 2479855 2479860 2479852 2479880 2479849 2479847 2479848 2479840 2476492

CVEs

CVE-2026-8388 CVE-2026-8391 CVE-2026-8401 CVE-2026-8946 CVE-2026-8947 CVE-2026-8950 CVE-2026-8953 CVE-2026-8954 CVE-2026-8955 CVE-2026-8956 CVE-2026-8957 CVE-2026-8958 CVE-2026-8961 CVE-2026-8962 CVE-2026-8968 CVE-2026-8970 CVE-2026-8974 CVE-2026-8975

Affected packages

Rocky Linux 10 ppc64le - AppStream

firefox-debugsource-0:140.11.0-1.el10_2.ppc64le.rpm firefox-debuginfo-0:140.11.0-1.el10_2.ppc64le.rpm firefox-0:140.11.0-1.el10_2.ppc64le.rpm firefox-0:140.11.0-1.el10_2.src.rpm

Rocky Linux 10 aarch64 - AppStream

firefox-debuginfo-0:140.11.0-1.el10_2.aarch64.rpm firefox-0:140.11.0-1.el10_2.aarch64.rpm firefox-debugsource-0:140.11.0-1.el10_2.aarch64.rpm firefox-0:140.11.0-1.el10_2.src.rpm

Rocky Linux 10 s390x - AppStream

firefox-debuginfo-0:140.11.0-1.el10_2.s390x.rpm firefox-0:140.11.0-1.el10_2.s390x.rpm firefox-0:140.11.0-1.el10_2.src.rpm firefox-debugsource-0:140.11.0-1.el10_2.s390x.rpm

Rocky Linux 10 x86_64 - AppStream

firefox-debugsource-0:140.11.0-1.el10_2.x86_64.rpm firefox-debuginfo-0:140.11.0-1.el10_2.x86_64.rpm firefox-0:140.11.0-1.el10_2.src.rpm firefox-0:140.11.0-1.el10_2.x86_64.rpm

Rocky Linux 10 riscv64 - AppStream

firefox-0:140.11.0-1.el10_2.src.rpm