Red Hat Security Advisory: firefox security update
🔗 CVE IDs covered (33)
📋 Description
CVE-2026-15718 — firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719 — firefox: thunderbird: Site isolation issue in the DOM: Navigation component CVE-2026-16349 — firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component CVE-2026-16350 — firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component CVE-2026-16351 — firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-16352 — firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-16353 — firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component CVE-2026-16354 — firefox: thunderbird: Information disclosure in the Graphics: ImageLib component CVE-2026-16355 — firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component CVE-2026-16356 — firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-16357 — firefox: thunderbird: Incorrect boundary conditions in the Graphics component CVE-2026-16358 — firefox: thunderbird: Site isolation issue in the Graphics: WebRender component CVE-2026-16359 — firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component CVE-2026-16360 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 CVE-2026-16361 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 CVE-2026-16362 — firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component CVE-2026-16363 — firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component CVE-2026-16368 — firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component CVE-2026-16369 — firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component CVE-2026-16371 — firefox: thunderbird: Privilege escalation in the DOM: Navigation component CVE-2026-16374 — firefox: thunderbird: Information disclosure in the Framework component in DevTools CVE-2026-16375 — firefox: thunderbird: Site isolation issue in the Networking: HTTP component CVE-2026-16377 — firefox: thunderbird: Mitigation bypass in the PDF Viewer component CVE-2026-16379 — firefox: thunderbird: Privilege escalation in the DOM: Content Processes component CVE-2026-16381 — firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component CVE-2026-16383 — firefox: thunderbird: Mitigation bypass in the DOM: Networking component CVE-2026-16387 — firefox: thunderbird: Site isolation issue in the Networking component CVE-2026-16390 — firefox: thunderbird: Mitigation bypass in the Enterprise Policies component CVE-2026-16391 — firefox: thunderbird: Information disclosure in the Storage: IndexedDB component CVE-2026-16396 — firefox: thunderbird: Privilege escalation in WebExtensions CVE-2026-16405 — firefox: thunderbird: Information disclosure in the Networking: WebSockets component CVE-2026-16412 — firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 CVE-2026-56208 — libaom: libaom: heap buffer overflow in AV1 encoder first-pass stats buffer via LAP mode
🎯 Affected products14
- Red Hat Enterprise Linux AppStream (v. 8)
- firefox-0:140.13.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-0:140.13.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-0:140.13.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-0:140.13.0-1.el8_10.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-0:140.13.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-debuginfo-0:140.13.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-debuginfo-0:140.13.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-debuginfo-0:140.13.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-debuginfo-0:140.13.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-debugsource-0:140.13.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-debugsource-0:140.13.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-debugsource-0:140.13.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- firefox-debugsource-0:140.13.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: There is no complete mitigation for this vulnerability. The following measures can reduce risk: 1. If using libaom as a standalone encoder library, avoid setting g_lag_in_frames to values >= 1 when processing untrusted input, or validate all encoder configuration parameters before passing them to the libaom API. 2. For Firefox and Thunderbird, ensure browsers are updated to versions that include the patched libaom (v3.14.0 or later). 3. For standalone libaom deployments (RHEL-AI, Hummingbird), restrict access to the encoding service to trusted clients only. 4. Apply network-level access controls to limit who can submit video for encoding.
🔗 References (36)
- selfhttps://access.redhat.com/errata/RHSA-2026:47105
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2490799
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2499973
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2499974
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503415
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503420
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503425
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503430
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503432
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503439
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503444
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503451
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503454
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503472
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503485
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503489
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503491
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503498
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503500
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503501
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503505
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503512
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503513
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2503527
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47105.json