Red Hat Security Advisory: firefox security update
🔗 CVE IDs covered (28)
📋 Description
CVE-2026-92005 — firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component CVE-2026-92006 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92007 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92008 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92009 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92010 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92011 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92012 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92013 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92014 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component CVE-2026-92015 — firefox: thunderbird: Privilege escalation in the WebExtensions component CVE-2026-92016 — firefox: thunderbird: Use-after-free in the Disability Access APIs component CVE-2026-92017 — firefox: thunderbird: Privilege escalation in the DOM: Service Workers component CVE-2026-92018 — firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component CVE-2026-92019 — firefox: thunderbird: Mitigation bypass in the Remote Settings Client component CVE-2026-92020 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component CVE-2026-92021 — firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component CVE-2026-92022 — firefox: thunderbird: Use-after-free in the DOM: HTML Parser component CVE-2026-92023 — firefox: thunderbird: Use-after-free in the XML component CVE-2026-92024 — firefox: thunderbird: Use-after-free in the SVG component CVE-2026-92025 — firefox: thunderbird: Use-after-free in the DOM: Navigation component CVE-2026-92026 — firefox: thunderbird: Use-after-free in the Networking component CVE-2026-92027 — firefox: thunderbird: Use-after-free in the DOM: Streams component CVE-2026-92028 — firefox: thunderbird: Use-after-free in the DOM: Core & HTML component CVE-2026-92029 — firefox: thunderbird: Use-after-free in the SVG component CVE-2026-92030 — firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component CVE-2026-92031 — firefox: thunderbird: Information disclosure in the Graphics: ImageLib component CVE-2026-92032 — firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component
🎯 Affected products14
- Red Hat Enterprise Linux AppStream (v. 10)
- firefox-0:140.16.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-0:140.16.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-0:140.16.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-0:140.16.0-1.el10_2.src as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-0:140.16.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-debuginfo-0:140.16.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-debuginfo-0:140.16.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-debuginfo-0:140.16.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-debugsource-0:140.16.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-debugsource-0:140.16.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-debugsource-0:140.16.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- firefox-debugsource-0:140.16.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (31)
- selfhttps://access.redhat.com/errata/RHSA-2026:69461
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533737
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533740
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533741
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533742
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533743
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533747
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533751
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533753
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533758
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533762
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533764
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533769
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533770
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533771
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533774
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533778
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533779
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533781
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533790
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533792
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533797
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2533799
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_69461.json