Security News

Cybersecurity news aggregator

🦊
HIGH Updates Red Hat Errata

RHSA-2026:58899: Important: firefox security update

This Red Hat advisory addresses multiple Important-rated vulnerabilities in Firefox and Thunderbird, including a high-severity DLP mitigation bypass (CVE-2026-74983, CVSS 8.1) and a high-severity privilege escalation in the Cookies component (CVE-2026-74953, CVSS 8.8). Affected versions include Mozilla Firefox versions prior to 140.14.0 and versions 141.0 through 153.1.0, requiring an update to version 140.14.0 or 153.1.0. The update also resolves numerous other flaws such as use-after-free, information disclosure, and site isolation issues across various browser components.
Read Full Article →

Red Hat Product Errata RHSA-2026:58899 - Security Advisory Issued: 2026-08-24 Updated: 2026-08-24 RHSA-2026:58899 - Security Advisory Overview Updated Packages Synopsis Important: firefox security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for firefox is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983) firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934) firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953) firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987) firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948) firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943) firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component (CVE-2026-74971) firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941) firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965) firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946) firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973) firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949) firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74990) firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component (CVE-2026-74936) firefox: thunderbird: Use-after-free in the Graphics: Text component (CVE-2026-74940) firefox: thunderbird: Site isolation issue in the WebExtensions component (CVE-2026-74960) firefox: thunderbird: Use-after-free in the Layout: Text and Fonts component (CVE-2026-74969) firefox: thunderbird: Mitigation bypass in the Storage: Cache API component (CVE-2026-74959) firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-74976) firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component (CVE-2026-74974) firefox: thunderbird: Mitigation bypass in the Safe Browsing component (CVE-2026-74957) firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component (CVE-2026-74967) firefox: Privilege escalation in the Remote Settings Client component (CVE-2026-74942) firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-74939) firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component (CVE-2026-74972) firefox: thunderbird: Information disclosure in the Graphics: Text component (CVE-2026-74945) firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-74963) firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-74944) firefox: Integer overflow in the Graphics component (CVE-2026-74964) firefox: Site isolation issue in the Networking: Cookies component (CVE-2026-74962) firefox: thunderbird: Privilege escalation in the DOM: Networking component (CVE-2026-74935) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2517819 - CVE-2026-74983 firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component BZ - 2517820 - CVE-2026-74934 firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component BZ - 2517822 - CVE-2026-74953 firefox: thunderbird: Privilege escalation in the Networking: Cookies component BZ - 2517823 - CVE-2026-74987 firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 BZ - 2517825 - CVE-2026-74948 firefox: thunderbird: Information disclosure in the Graphics component BZ - 2517826 - CVE-2026-74943 firefox: thunderbird: Use-after-free in the Graphics: ImageLib component BZ - 2517831 - CVE-2026-74971 firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component BZ - 2517833 - CVE-2026-74941 firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component BZ - 2517834 - CVE-2026-74965 firefox: Privilege escalation in the Shell Integration component BZ - 2517835 - CVE-2026-74946 firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component BZ - 2517836 - CVE-2026-74973 firefox: Race condition, use-after-free in the Graphics component BZ - 2517837 - CVE-2026-74949 firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component BZ - 2517839 - CVE-2026-74990 firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 BZ - 2517840 - CVE-2026-74936 firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component BZ - 2517841 - CVE-2026-74940 firefox: thunderbird: Use-after-free in the Graphics: Text component BZ - 2517845 - CVE-2026-74960 firefox: thunderbird: Site isolation issue in the WebExtensions component BZ - 2517846 - CVE-2026-74969 firefox: thunderbird: Use-after-free in the Layout: Text and Fonts component BZ - 2517849 - CVE-2026-74959 firefox: thunderbird: Mitigation bypass in the Storage: Cache API component BZ - 2517851 - CVE-2026-74976 firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component BZ - 2517853 - CVE-2026-74974 firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component BZ - 2517856 - CVE-2026-74957 firefox: thunderbird: Mitigation bypass in the Safe Browsing component BZ - 2517858 - CVE-2026-74967 firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component BZ - 2517859 - CVE-2026-74942 firefox: Privilege escalation in the Remote Settings Client component BZ - 2517860 - CVE-2026-74939 firefox: thunderbird: Privilege escalation in the DOM: Navigation component BZ - 2517862 - CVE-2026-74972 firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component BZ - 2517863 - CVE-2026-74945 firefox: thunderbird: Information disclosure in the Graphics: Text component BZ - 2517866 - CVE-2026-74963 firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component BZ - 2517868 - CVE-2026-74944 firefox: thunderbird: Use-after-free in the DOM: Core & HTML component BZ - 2517870 - CVE-2026-74964 firefox: Integer overflow in the Graphics component BZ - 2517872 - CVE-2026-74962 firefox: Site isolation issue in the Networking: Cookies component BZ - 2517874 - CVE-2026-74935 firefox: thunderbird: Privilege escalation in the DOM: Networking component CVEs CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74948 CVE-2026-74949 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959 CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74967 CVE-2026-74969 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74983 CVE-2026-74987 CVE-2026-74990 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM firefox-140.14.0-1.el10_2.src.rpm SHA-256: 41d7a3062b239206ea968e940d11a7703f948617f53535ef5970ec52e7e0bc36 x86_64 firefox-140.14.0-1.el10_2.x86_64.rpm SHA-256: f561a64df9211f6450b288c7def7fb21720a0894a8e66c2641f2eda2ded7d6ed firefox-debuginfo-140.14.0-1.el10_2.x86_64.rpm SHA-256: 867a9a263d8b6a909b92c56bb64c60d21d5cba6504a849ecd4436f829275faa9 firefox-debugsource-140.14.0-1.el10_2.x86_64.rpm SHA-256: 84917d513cbf48b0b08d63f404a391ce02fb883db6cb7a6ce5ca40d9b96206b0 Red Hat Enterprise Linux for

Share this article