[Apollo] Advisories Statistics light light Login

RLSA-2026:58899

Security Mirrored from RHSA-2026:58899
Issued at: 2026-08-25
Updated at: 2026-08-25

Advisory content derived from Red Hat RHSA-2026:58899, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: firefox security update



Description

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

* firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983)

* firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934)

* firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953)

* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987)

* firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948)

* firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943)

* firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component (CVE-2026-74971)

* firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941)

* firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965)

* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946)

* firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973)

* firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949)

* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74990)

* firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component (CVE-2026-74936)

* firefox: thunderbird: Use-after-free in the Graphics: Text component (CVE-2026-74940)

* firefox: thunderbird: Site isolation issue in the WebExtensions component (CVE-2026-74960)

* firefox: thunderbird: Use-after-free in the Layout: Text and Fonts component (CVE-2026-74969)

* firefox: thunderbird: Mitigation bypass in the Storage: Cache API component (CVE-2026-74959)

* firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-74976)

* firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component (CVE-2026-74974)

* firefox: thunderbird: Mitigation bypass in the Safe Browsing component (CVE-2026-74957)

* firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component (CVE-2026-74967)

* firefox: Privilege escalation in the Remote Settings Client component (CVE-2026-74942)

* firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-74939)

* firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component (CVE-2026-74972)

* firefox: thunderbird: Information disclosure in the Graphics: Text component (CVE-2026-74945)

* firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-74963)

* firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-74944)

* firefox: Integer overflow in the Graphics component (CVE-2026-74964)

* firefox: Site isolation issue in the Networking: Cookies component (CVE-2026-74962)

* firefox: thunderbird: Privilege escalation in the DOM: Networking component (CVE-2026-74935)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 10 aarch64 Rocky Linux 10 ppc64le Rocky Linux 10 riscv64 Rocky Linux 10 s390x Rocky Linux 10 x86_64

Fixes

2517866 2517874 2517834 2517845 2517859 2517825 2517849 2517840 2517831 2517820 2517826 2517846 2517836 2517841 2517863 2517872 2517833 2517868 2517823 2517853 2517822 2517870 2517819 2517862 2517851 2517839 2517860 2517856 2517837 2517858 2517835

CVEs

CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74948 CVE-2026-74949 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959 CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74967 CVE-2026-74969 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74983 CVE-2026-74987 CVE-2026-74990

Affected packages

Rocky Linux 10 ppc64le - AppStream

firefox-0:140.14.0-1.el10_2.ppc64le.rpm firefox-debugsource-0:140.14.0-1.el10_2.ppc64le.rpm firefox-0:140.14.0-1.el10_2.src.rpm firefox-debuginfo-0:140.14.0-1.el10_2.ppc64le.rpm

Rocky Linux 10 s390x - AppStream

firefox-debuginfo-0:140.14.0-1.el10_2.s390x.rpm firefox-0:140.14.0-1.el10_2.src.rpm firefox-0:140.14.0-1.el10_2.s390x.rpm firefox-debugsource-0:140.14.0-1.el10_2.s390x.rpm

Rocky Linux 10 aarch64 - AppStream

firefox-debugsource-0:140.14.0-1.el10_2.aarch64.rpm firefox-0:140.14.0-1.el10_2.src.rpm firefox-0:140.14.0-1.el10_2.aarch64.rpm firefox-debuginfo-0:140.14.0-1.el10_2.aarch64.rpm

Rocky Linux 10 riscv64 - AppStream

firefox-0:140.14.0-1.el10_2.src.rpm

Rocky Linux 10 x86_64 - AppStream

firefox-0:140.14.0-1.el10_2.src.rpm firefox-0:140.14.0-1.el10_2.x86_64.rpm firefox-debugsource-0:140.14.0-1.el10_2.x86_64.rpm firefox-debuginfo-0:140.14.0-1.el10_2.x86_64.rpm