RHSA-2026:76741HighCVSS 7.5

Red Hat Security Advisory: firefox security update

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-16365 — firefox: thunderbird: Privilege escalation in the DOM: Workers component CVE-2026-75874 — firefox: thunderbird: Sandbox escape in the Remote Settings Client component CVE-2026-84119 — firefox: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-84120 — firefox: Use-after-free in the Audio/Video component CVE-2026-84121 — firefox: Sandbox escape due to use-after-free in the DOM: Security component CVE-2026-84122 — firefox: Use-after-free in the Audio/Video component CVE-2026-84124 — firefox: Use-after-free in the DOM: Core & HTML component CVE-2026-84131 — firefox: Privilege escalation due to invalid pointer in the Graphics component CVE-2026-84143 — firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 CVE-2026-84145 — firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40

🎯 Affected products9

  • Red Hat Enterprise Linux Server (v. 7 ELS)
  • firefox-0:140.15.0-1.el7_9.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • firefox-0:140.15.0-1.el7_9.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • firefox-0:140.15.0-1.el7_9.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • firefox-0:140.15.0-1.el7_9.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • firefox-0:140.15.0-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • firefox-debuginfo-0:140.15.0-1.el7_9.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • firefox-debuginfo-0:140.15.0-1.el7_9.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
  • firefox-debuginfo-0:140.15.0-1.el7_9.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (13)