[Apollo] Advisories Statistics light light Login

RLSA-2026:27717

Security Mirrored from RHSA-2026:27717
Issued at: 2026-06-25
Updated at: 2026-06-25

Synopsis

Important: firefox security update



Description

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

* firefox: thunderbird: Sandbox escape in the DOM: Workers component (CVE-2026-12294)

* firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12313)

* firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12311)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12290)

* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12327)

* firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component (CVE-2026-12299)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12329)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12312)

* firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12302)

* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12328)

* firefox: thunderbird: Incorrect boundary conditions in the Internationalization component (CVE-2026-12330)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12314)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12309)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12310)

* firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component (CVE-2026-12325)

* firefox: thunderbird: Sandbox escape in the DOM: Navigation component (CVE-2026-12295)

* firefox: thunderbird: Privilege escalation in the Graphics: WebRender component (CVE-2026-12289)

* firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12315)

* firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component (CVE-2026-12296)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12306)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12307)

* firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component (CVE-2026-12297)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12305)

* firefox: thunderbird: Incorrect boundary conditions in the Web Audio component (CVE-2026-12292)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12308)

* firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-12324)

* firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-12304)

* firefox: thunderbird: Use-after-free in the Networking: HTTP component (CVE-2026-12291)

* firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 (CVE-2026-12298)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64 Rocky Linux 8 x86_64

Fixes

2489207 2489208 2489209 2489210 2489211 2489212 2489214 2489215 2489217 2489218 2489220 2489221 2489223 2489224 2489225 2489226 2489229 2489231 2489232 2489233 2489234 2489235 2489236 2489237 2489239 2489240 2489243 2489244 2489248

CVEs

CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329 CVE-2026-12330

Affected packages

Rocky Linux 8 aarch64 - AppStream

firefox-0:140.12.0-1.el8_10.aarch64.rpm firefox-0:140.12.0-1.el8_10.src.rpm firefox-debuginfo-0:140.12.0-1.el8_10.aarch64.rpm firefox-debugsource-0:140.12.0-1.el8_10.aarch64.rpm

Rocky Linux 8 x86_64 - AppStream

firefox-0:140.12.0-1.el8_10.src.rpm firefox-0:140.12.0-1.el8_10.x86_64.rpm firefox-debuginfo-0:140.12.0-1.el8_10.x86_64.rpm firefox-debugsource-0:140.12.0-1.el8_10.x86_64.rpm