[Apollo] Advisories Statistics light light Login

RLSA-2026:47101

Security Mirrored from RHSA-2026:47101
Issued at: 2026-07-30
Updated at: 2026-08-01

Synopsis

Important: firefox security update



Description

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

* firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719)

* firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718)

* firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390)

* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350)

* firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391)

* firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375)

* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356)

* firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363)

* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412)

* firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381)

* firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355)

* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361)

* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352)

* firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368)

* firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377)

* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360)

* firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362)

* firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358)

* firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387)

* firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349)

* firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357)

* firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351)

* firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371)

* firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379)

* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354)

* firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374)

* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359)

* firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383)

* firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369)

* firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353)

* firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396)

* firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 10 aarch64 Rocky Linux 10 ppc64le Rocky Linux 10 riscv64 Rocky Linux 10 s390x Rocky Linux 10 x86_64

Fixes

2503432 2503501 2503473 2503472 2503456 2503423 2503425 2503497 2503430 2503451 2503440 2503463 2503517 2503489 2503505 2503439 2503513 2503444 2499974 2503434 2503454 2503420 2503416 2499973 2503527 2503521 2503491 2503512 2503500 2503498 2503415 2503485

CVEs

CVE-2026-15718 CVE-2026-15719 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16361 CVE-2026-16362 CVE-2026-16363 CVE-2026-16368 CVE-2026-16369 CVE-2026-16371 CVE-2026-16374 CVE-2026-16375 CVE-2026-16377 CVE-2026-16379 CVE-2026-16381 CVE-2026-16383 CVE-2026-16387 CVE-2026-16390 CVE-2026-16391 CVE-2026-16396 CVE-2026-16405 CVE-2026-16412

Affected packages

Rocky Linux 10 aarch64 - AppStream

firefox-debugsource-0:140.13.0-1.el10_2.aarch64.rpm firefox-debuginfo-0:140.13.0-1.el10_2.aarch64.rpm firefox-0:140.13.0-1.el10_2.src.rpm firefox-0:140.13.0-1.el10_2.aarch64.rpm

Rocky Linux 10 ppc64le - AppStream

firefox-0:140.13.0-1.el10_2.ppc64le.rpm firefox-0:140.13.0-1.el10_2.src.rpm firefox-debugsource-0:140.13.0-1.el10_2.ppc64le.rpm firefox-debuginfo-0:140.13.0-1.el10_2.ppc64le.rpm

Rocky Linux 10 riscv64 - AppStream

firefox-0:140.13.0-1.el10_2.src.rpm

Rocky Linux 10 s390x - AppStream

firefox-0:140.13.0-1.el10_2.src.rpm firefox-debuginfo-0:140.13.0-1.el10_2.s390x.rpm firefox-0:140.13.0-1.el10_2.s390x.rpm firefox-debugsource-0:140.13.0-1.el10_2.s390x.rpm

Rocky Linux 10 x86_64 - AppStream

firefox-0:140.13.0-1.el10_2.src.rpm firefox-0:140.13.0-1.el10_2.x86_64.rpm firefox-debuginfo-0:140.13.0-1.el10_2.x86_64.rpm firefox-debugsource-0:140.13.0-1.el10_2.x86_64.rpm