[Apollo] Advisories Statistics light light Login

RLSA-2026:67129

Security Mirrored from RHSA-2026:67129
Issued at: 2026-09-27
Updated at: 2026-09-27

Advisory content derived from Red Hat RHSA-2026:67129, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: firefox security update



Description

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)

* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)

* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)

* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)

* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)

* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)

* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)

* firefox: Use-after-free in the DOM: Core & HTML component (CVE-2026-84124)

* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)

* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 10 aarch64 Rocky Linux 10 ppc64le Rocky Linux 10 riscv64 Rocky Linux 10 s390x Rocky Linux 10 x86_64

Fixes

2503504 2517832 2526753 2526760 2526764 2526765 2526767 2526773 2526778 2526781

CVEs

CVE-2026-16365 CVE-2026-75874 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84124 CVE-2026-84131 CVE-2026-84143 CVE-2026-84145

Affected packages

Rocky Linux 10 x86_64 - AppStream

firefox-debugsource-0:140.15.0-1.el10_2.x86_64.rpm firefox-0:140.15.0-1.el10_2.src.rpm firefox-0:140.15.0-1.el10_2.x86_64.rpm firefox-debuginfo-0:140.15.0-1.el10_2.x86_64.rpm

Rocky Linux 10 ppc64le - AppStream

firefox-debugsource-0:140.15.0-1.el10_2.ppc64le.rpm firefox-0:140.15.0-1.el10_2.src.rpm firefox-debuginfo-0:140.15.0-1.el10_2.ppc64le.rpm firefox-0:140.15.0-1.el10_2.ppc64le.rpm

Rocky Linux 10 aarch64 - AppStream

firefox-0:140.15.0-1.el10_2.src.rpm firefox-debugsource-0:140.15.0-1.el10_2.aarch64.rpm firefox-debuginfo-0:140.15.0-1.el10_2.aarch64.rpm firefox-0:140.15.0-1.el10_2.aarch64.rpm

Rocky Linux 10 riscv64 - AppStream

firefox-0:140.15.0-1.el10_2.src.rpm

Rocky Linux 10 s390x - AppStream

firefox-0:140.15.0-1.el10_2.src.rpm firefox-0:140.15.0-1.el10_2.s390x.rpm firefox-debugsource-0:140.15.0-1.el10_2.s390x.rpm firefox-debuginfo-0:140.15.0-1.el10_2.s390x.rpm