Red Hat Security Advisory: firefox security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2025-14327 — firefox: Spoofing issue in the Downloads Panel component CVE-2026-0877 — firefox: thunderbird: Mitigation bypass in the DOM: Security component CVE-2026-0878 — firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-0879 — firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics component CVE-2026-0880 — firefox: thunderbird: Sandbox escape due to integer overflow in the Graphics component CVE-2026-0882 — firefox: thunderbird: Use-after-free in the IPC component CVE-2026-0883 — firefox: thunderbird: Information disclosure in the Networking component CVE-2026-0884 — firefox: thunderbird: Use-after-free in the JavaScript Engine component CVE-2026-0885 — firefox: thunderbird: Use-after-free in the JavaScript: GC component CVE-2026-0886 — firefox: thunderbird: Incorrect boundary conditions in the Graphics component CVE-2026-0887 — firefox: thunderbird: Clickjacking issue, information disclosure in the PDF Viewer component CVE-2026-0890 — firefox: thunderbird: Spoofing issue in the DOM: Copy & Paste and Drag & Drop component CVE-2026-0891 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:2231
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2420507
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428961
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428963
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428965
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428966
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428967
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428968
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428969
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428971
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428973
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428975
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2428978
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2231.json