Red Hat Security Advisory: firefox security update
🔗 CVE IDs covered (29)
📋 Description
CVE-2026-12289 — firefox: thunderbird: Privilege escalation in the Graphics: WebRender component CVE-2026-12290 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12291 — firefox: thunderbird: Use-after-free in the Networking: HTTP component CVE-2026-12292 — firefox: thunderbird: Incorrect boundary conditions in the Web Audio component CVE-2026-12294 — firefox: thunderbird: Sandbox escape in the DOM: Workers component CVE-2026-12295 — firefox: thunderbird: Sandbox escape in the DOM: Navigation component CVE-2026-12296 — firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component CVE-2026-12297 — firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component CVE-2026-12298 — firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 CVE-2026-12299 — firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component CVE-2026-12302 — firefox: thunderbird: Mitigation bypass in the DOM: Security component CVE-2026-12304 — firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component CVE-2026-12305 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12306 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12307 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12308 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12309 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12310 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12311 — firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component CVE-2026-12312 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12313 — firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component CVE-2026-12314 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12315 — firefox: thunderbird: Mitigation bypass in the DOM: Security component CVE-2026-12324 — firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-12325 — firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component CVE-2026-12327 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 CVE-2026-12328 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 CVE-2026-12329 — firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 CVE-2026-12330 — firefox: thunderbird: Incorrect boundary conditions in the Internationalization component
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2026:27733
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489207
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489208
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489209
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489212
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489214
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489215
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489218
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489221
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489223
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489224
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489225
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489226
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489229
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489231
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489232
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489233
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489234
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489235
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489236
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489237
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489239
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489240
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489243
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489244
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489248
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_27733.json