Security News

Cybersecurity news aggregator

🩊
HIGH Updates Red Hat Errata

RHSA-2026:36100: Important: firefox security update

This Red Hat security advisory addresses multiple critical vulnerabilities in Firefox and Thunderbird, including sandbox escapes, memory safety bugs, and mitigation bypasses, which could lead to remote code execution and privilege escalation. The most severe listed CVE is CVE-2026-12294 with a CVSS 3.1 score of 9.6 (CRITICAL). Affected versions include Mozilla Firefox prior to 115.37.0, prior to 152.0.0, and versions 128.0 through 140.12.0, as well as Thunderbird prior to 140.12.0 and 152.0.0; these are fixed in Firefox 115.37.0, 140.12.0, and 152.0.0, and Thunderbird 140.12.0 and 152.0.0.
Read Full Article →

Errata des produits Red Hat RHSA-2026:36100 - Security Advisory PubliĂ© : 2026-07-07 Mis Ă  jour : 2026-07-07 RHSA-2026:36100 - Security Advisory Aperçu gĂ©nĂ©ral Paquets mis Ă  jour Synopsis Important: firefox security update Type / SĂ©vĂ©ritĂ© Security Advisory: Important Analyse des correctifs dans Red Hat Insights Identifiez et remĂ©diez aux systĂšmes concernĂ©s par cette alerte. Voir les systĂšmes concernĂ©s Sujet An update for firefox is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): firefox: thunderbird: Sandbox escape in the DOM: Workers component (CVE-2026-12294) firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12313) firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12311) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12290) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12327) firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component (CVE-2026-12299) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12329) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12312) firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12302) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12328) firefox: thunderbird: Incorrect boundary conditions in the Internationalization component (CVE-2026-12330) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12314) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12309) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12310) firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component (CVE-2026-12325) firefox: thunderbird: Sandbox escape in the DOM: Navigation component (CVE-2026-12295) firefox: thunderbird: Privilege escalation in the Graphics: WebRender component (CVE-2026-12289) firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12315) firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component (CVE-2026-12296) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12306) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12307) firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component (CVE-2026-12297) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12305) firefox: thunderbird: Incorrect boundary conditions in the Web Audio component (CVE-2026-12292) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12308) firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-12324) firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-12304) firefox: thunderbird: Use-after-free in the Networking: HTTP component (CVE-2026-12291) firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 (CVE-2026-12298) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Produits concernĂ©s Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Correctifs BZ - 2489207 - CVE-2026-12294 firefox: thunderbird: Sandbox escape in the DOM: Workers component BZ - 2489208 - CVE-2026-12313 firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component BZ - 2489209 - CVE-2026-12311 firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component BZ - 2489210 - CVE-2026-12290 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489211 - CVE-2026-12327 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 BZ - 2489212 - CVE-2026-12299 firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component BZ - 2489214 - CVE-2026-12329 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489215 - CVE-2026-12312 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489217 - CVE-2026-12302 firefox: thunderbird: Mitigation bypass in the DOM: Security component BZ - 2489218 - CVE-2026-12328 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 BZ - 2489220 - CVE-2026-12330 firefox: thunderbird: Incorrect boundary conditions in the Internationalization component BZ - 2489221 - CVE-2026-12314 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489223 - CVE-2026-12309 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489224 - CVE-2026-12310 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489225 - CVE-2026-12325 firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component BZ - 2489226 - CVE-2026-12295 firefox: thunderbird: Sandbox escape in the DOM: Navigation component BZ - 2489229 - CVE-2026-12289 firefox: thunderbird: Privilege escalation in the Graphics: WebRender component BZ - 2489231 - CVE-2026-12315 firefox: thunderbird: Mitigation bypass in the DOM: Security component BZ - 2489232 - CVE-2026-12296 firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component BZ - 2489233 - CVE-2026-12306 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489234 - CVE-2026-12307 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489235 - CVE-2026-12297 firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component BZ - 2489236 - CVE-2026-12305 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489237 - CVE-2026-12292 firefox: thunderbird: Incorrect boundary conditions in the Web Audio component BZ - 2489239 - CVE-2026-12308 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489240 - CVE-2026-12324 firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component BZ - 2489243 - CVE-2026-12304 firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component BZ - 2489244 - CVE-2026-12291 firefox: thunderbird: Use-after-free in the Networking: HTTP component BZ - 2489248 - CVE-2026-12298 firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 CVE CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329 CVE-2026-12330 RĂ©fĂ©rences https://access.redhat.com/security/updates/classification/#important Remarque: Il existe peut-ĂȘtre des versions plus rĂ©centes de ces paquets. Cliquer sur un nom de paquet pour obtenir plus de dĂ©tails. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM firefox-140.12.0-1.el10_0.src.rpm SHA-256: 68625e76d5456785009bfe8a701981b27cbc603f4c258dc2ca1b889b38f8c768 x86_64 firefox-140.12.0-1.el10_0.x86_64.rpm SHA-256: 5c892286b39e18b7988b878d3c619c5637a6e42ef22bd912027b04c81c7cabd1 firefox-debuginfo-140.12.0-1.el10_0.x86_64.rpm SHA-256: bcc213af4ffa291c86981e5b07513e6be38da1ed229c23bb4b467c3564ff6204 firefox-debugsource-140.12.0-1.el10_0.x86_64.rpm SHA-256: e9324cd8a6b7343528ace2c44a1327c3b3ddb66aa4459443502d12eb7bc8335a Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM firefox-140.12.0-1.el10_0.src.rpm SHA-256: 68625e76d5456785009bfe8a701981b27cbc603f4c258dc2ca1b889b38f8c768 s390x firefox-140.12.0-1.el10_0.s390x.rpm SHA-256: a8707e82783f0686554786d7ed75856d912425108c80ff440bde15ca62dbb92e firefox-debuginfo-140.12.0-1.el10_0.s390x.rpm SHA-256: 2f7fecb05b00a7de3ab4cb0a7eb9ff0e3a8b151a22733590727275fb18f4f932 firefox-debugsource-140.12.0-1.el10_0.s390x.rpm SHA-256: 2f0af6d9459f50fc29410209ac3b8fca8770f10626f94a42910c1c6c637b6eca Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM firefox-140.12.0-1.el10_0.src.rpm SHA-256: 68625e76d5456785009bfe8a701981b27cbc603f4c258dc2ca1b889b38f8c768 ppc64le firefox-140.12.0

Share this article