{"document":{"aggregate_severity":{"namespace":"https://access.redhat.com/security/updates/classification/","text":"Important"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"text":"Copyright © Red Hat, Inc. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"An update for firefox is now available for Red Hat Enterprise Linux 10.\n\nRed Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.","title":"Topic"},{"category":"general","text":"Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.\n\nSecurity Fix(es):\n\n* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)\n\n* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)\n\n* firefox: thunderbird: Use-after-free in the Networking component (CVE-2026-92026)\n\n* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-92031)\n\n* firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component (CVE-2026-92032)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92010)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92006)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92011)\n\n* firefox: thunderbird: Use-after-free in the DOM: Streams component (CVE-2026-92027)\n\n* firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-92028)\n\n* firefox: thunderbird: Privilege escalation in the WebExtensions component (CVE-2026-92015)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92013)\n\n* firefox: thunderbird: Use-after-free in the Disability Access APIs component (CVE-2026-92016)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92012)\n\n* firefox: thunderbird: Use-after-free in the DOM: HTML Parser component (CVE-2026-92022)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component (CVE-2026-92014)\n\n* firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component (CVE-2026-92018)\n\n* firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component (CVE-2026-92021)\n\n* firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component (CVE-2026-92005)\n\n* firefox: thunderbird: Privilege escalation in the DOM: Service Workers component (CVE-2026-92017)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92009)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component (CVE-2026-92020)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92008)\n\n* firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component (CVE-2026-92030)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92007)\n\n* firefox: thunderbird: Use-after-free in the DOM: Navigation component (CVE-2026-92025)\n\n* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92029)\n\n* firefox: thunderbird: Use-after-free in the XML component (CVE-2026-92023)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","title":"Details"},{"category":"legal_disclaimer","text":"This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"https://access.redhat.com/security/team/contact/","issuing_authority":"Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.","name":"Red Hat Product Security","namespace":"https://www.redhat.com"},"references":[{"category":"self","summary":"https://access.redhat.com/errata/RHSA-2026:69461","url":"https://access.redhat.com/errata/RHSA-2026:69461"},{"category":"external","summary":"https://access.redhat.com/security/updates/classification/#important","url":"https://access.redhat.com/security/updates/classification/#important"},{"category":"external","summary":"2533737","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533737"},{"category":"external","summary":"2533740","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533740"},{"category":"external","summary":"2533741","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533741"},{"category":"external","summary":"2533742","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533742"},{"category":"external","summary":"2533743","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533743"},{"category":"external","summary":"2533747","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533747"},{"category":"external","summary":"2533751","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533751"},{"category":"external","summary":"2533753","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533753"},{"category":"external","summary":"2533757","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533757"},{"category":"external","summary":"2533758","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533758"},{"category":"external","summary":"2533760","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533760"},{"category":"external","summary":"2533762","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533762"},{"category":"external","summary":"2533764","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533764"},{"category":"external","summary":"2533769","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533769"},{"category":"external","summary":"2533770","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533770"},{"category":"external","summary":"2533771","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533771"},{"category":"external","summary":"2533773","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533773"},{"category":"external","summary":"2533774","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533774"},{"category":"external","summary":"2533778","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533778"},{"category":"external","summary":"2533779","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533779"},{"category":"external","summary":"2533781","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533781"},{"category":"external","summary":"2533786","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533786"},{"category":"external","summary":"2533790","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533790"},{"category":"external","summary":"2533791","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533791"},{"category":"external","summary":"2533792","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533792"},{"category":"external","summary":"2533793","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533793"},{"category":"external","summary":"2533797","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533797"},{"category":"external","summary":"2533799","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533799"},{"category":"self","summary":"Canonical URL","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_69461.json"}],"title":"Red Hat Security Advisory: firefox security update","tracking":{"current_release_date":"2026-09-22T22:26:45+00:00","generator":{"date":"2026-09-22T22:26:45+00:00","engine":{"name":"Red Hat SDEngine","version":"5.4.0"}},"id":"RHSA-2026:69461","initial_release_date":"2026-09-21T18:15:50+00:00","revision_history":[{"date":"2026-09-21T18:15:50+00:00","number":"1","summary":"Initial version"},{"date":"2026-09-21T18:15:50+00:00","number":"2","summary":"Last updated version"},{"date":"2026-09-22T22:26:45+00:00","number":"3","summary":"Last generated version"}],"status":"final","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Red Hat Enterprise Linux AppStream (v. 10)","product":{"name":"Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z","product_identification_helper":{"cpe":"cpe:/o:redhat:enterprise_linux:10.2"}}}],"category":"product_family","name":"Red Hat Enterprise Linux"},{"branches":[{"category":"product_version","name":"firefox-0:140.16.0-1.el10_2.src","product":{"name":"firefox-0:140.16.0-1.el10_2.src","product_id":"firefox-0:140.16.0-1.el10_2.src","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox@140.16.0-1.el10_2?arch=src"}}}],"category":"architecture","name":"src"},{"branches":[{"category":"product_version","name":"firefox-0:140.16.0-1.el10_2.aarch64","product":{"name":"firefox-0:140.16.0-1.el10_2.aarch64","product_id":"firefox-0:140.16.0-1.el10_2.aarch64","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox@140.16.0-1.el10_2?arch=aarch64"}}},{"category":"product_version","name":"firefox-debugsource-0:140.16.0-1.el10_2.aarch64","product":{"name":"firefox-debugsource-0:140.16.0-1.el10_2.aarch64","product_id":"firefox-debugsource-0:140.16.0-1.el10_2.aarch64","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox-debugsource@140.16.0-1.el10_2?arch=aarch64"}}},{"category":"product_version","name":"firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","product":{"name":"firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","product_id":"firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox-debuginfo@140.16.0-1.el10_2?arch=aarch64"}}}],"category":"architecture","name":"aarch64"},{"branches":[{"category":"product_version","name":"firefox-0:140.16.0-1.el10_2.ppc64le","product":{"name":"firefox-0:140.16.0-1.el10_2.ppc64le","product_id":"firefox-0:140.16.0-1.el10_2.ppc64le","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox@140.16.0-1.el10_2?arch=ppc64le"}}},{"category":"product_version","name":"firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","product":{"name":"firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","product_id":"firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox-debugsource@140.16.0-1.el10_2?arch=ppc64le"}}},{"category":"product_version","name":"firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","product":{"name":"firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","product_id":"firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox-debuginfo@140.16.0-1.el10_2?arch=ppc64le"}}}],"category":"architecture","name":"ppc64le"},{"branches":[{"category":"product_version","name":"firefox-0:140.16.0-1.el10_2.s390x","product":{"name":"firefox-0:140.16.0-1.el10_2.s390x","product_id":"firefox-0:140.16.0-1.el10_2.s390x","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox@140.16.0-1.el10_2?arch=s390x"}}},{"category":"product_version","name":"firefox-debugsource-0:140.16.0-1.el10_2.s390x","product":{"name":"firefox-debugsource-0:140.16.0-1.el10_2.s390x","product_id":"firefox-debugsource-0:140.16.0-1.el10_2.s390x","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox-debugsource@140.16.0-1.el10_2?arch=s390x"}}},{"category":"product_version","name":"firefox-debuginfo-0:140.16.0-1.el10_2.s390x","product":{"name":"firefox-debuginfo-0:140.16.0-1.el10_2.s390x","product_id":"firefox-debuginfo-0:140.16.0-1.el10_2.s390x","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox-debuginfo@140.16.0-1.el10_2?arch=s390x"}}}],"category":"architecture","name":"s390x"},{"branches":[{"category":"product_version","name":"firefox-0:140.16.0-1.el10_2.x86_64","product":{"name":"firefox-0:140.16.0-1.el10_2.x86_64","product_id":"firefox-0:140.16.0-1.el10_2.x86_64","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox@140.16.0-1.el10_2?arch=x86_64"}}},{"category":"product_version","name":"firefox-debugsource-0:140.16.0-1.el10_2.x86_64","product":{"name":"firefox-debugsource-0:140.16.0-1.el10_2.x86_64","product_id":"firefox-debugsource-0:140.16.0-1.el10_2.x86_64","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox-debugsource@140.16.0-1.el10_2?arch=x86_64"}}},{"category":"product_version","name":"firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","product":{"name":"firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","product_id":"firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","product_identification_helper":{"purl":"pkg:rpm/redhat/firefox-debuginfo@140.16.0-1.el10_2?arch=x86_64"}}}],"category":"architecture","name":"x86_64"}],"category":"vendor","name":"Red Hat"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"firefox-0:140.16.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64"},"product_reference":"firefox-0:140.16.0-1.el10_2.aarch64","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-0:140.16.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le"},"product_reference":"firefox-0:140.16.0-1.el10_2.ppc64le","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-0:140.16.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x"},"product_reference":"firefox-0:140.16.0-1.el10_2.s390x","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-0:140.16.0-1.el10_2.src as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src"},"product_reference":"firefox-0:140.16.0-1.el10_2.src","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-0:140.16.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64"},"product_reference":"firefox-0:140.16.0-1.el10_2.x86_64","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-debuginfo-0:140.16.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64"},"product_reference":"firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le"},"product_reference":"firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-debuginfo-0:140.16.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x"},"product_reference":"firefox-debuginfo-0:140.16.0-1.el10_2.s390x","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-debuginfo-0:140.16.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64"},"product_reference":"firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-debugsource-0:140.16.0-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64"},"product_reference":"firefox-debugsource-0:140.16.0-1.el10_2.aarch64","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-debugsource-0:140.16.0-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le"},"product_reference":"firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-debugsource-0:140.16.0-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x"},"product_reference":"firefox-debugsource-0:140.16.0-1.el10_2.s390x","relates_to_product_reference":"AppStream-10.2.Z"},{"category":"default_component_of","full_product_name":{"name":"firefox-debugsource-0:140.16.0-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)","product_id":"AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"},"product_reference":"firefox-debugsource-0:140.16.0-1.el10_2.x86_64","relates_to_product_reference":"AppStream-10.2.Z"}]},"vulnerabilities":[{"cve":"CVE-2026-92005","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T12:55:21.959142+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533778"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the Audio/Video: Web Codecs component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92005"},{"category":"external","summary":"RHBZ#2533778","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533778"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92005","url":"https://www.cve.org/CVERecord?id=CVE-2026-92005"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92005","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92005"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92005","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92005"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92005","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92005"}],"release_date":"2026-09-15T12:33:24.503000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component"},{"cve":"CVE-2026-92006","cwe":{"id":"CWE-653","name":"Improper Isolation or Compartmentalization"},"discovery_date":"2026-09-15T12:47:51.202612+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533751"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92006"},{"category":"external","summary":"RHBZ#2533751","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533751"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92006","url":"https://www.cve.org/CVERecord?id=CVE-2026-92006"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92006","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92006"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92006","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92006"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92006","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92006"}],"release_date":"2026-09-15T12:33:25.605000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component"},{"cve":"CVE-2026-92007","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"discovery_date":"2026-09-15T13:00:05.750680+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533792"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92007"},{"category":"external","summary":"RHBZ#2533792","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533792"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92007","url":"https://www.cve.org/CVERecord?id=CVE-2026-92007"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92007","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92007"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92007","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92007"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92007","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92007"}],"release_date":"2026-09-15T12:33:26.646000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component"},{"cve":"CVE-2026-92008","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"discovery_date":"2026-09-15T12:59:46.460598+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533790"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92008"},{"category":"external","summary":"RHBZ#2533790","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533790"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92008","url":"https://www.cve.org/CVERecord?id=CVE-2026-92008"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92008","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92008"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92008","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92008"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92008","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92008"}],"release_date":"2026-09-15T12:33:27.684000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component"},{"cve":"CVE-2026-92009","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"discovery_date":"2026-09-15T12:56:01.316710+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533781"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92009"},{"category":"external","summary":"RHBZ#2533781","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533781"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92009","url":"https://www.cve.org/CVERecord?id=CVE-2026-92009"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92009","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92009"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92009","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92009"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92009","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92009"}],"release_date":"2026-09-15T12:33:28.728000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component"},{"cve":"CVE-2026-92010","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"discovery_date":"2026-09-15T12:46:38.868486+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533747"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92010"},{"category":"external","summary":"RHBZ#2533747","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533747"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92010","url":"https://www.cve.org/CVERecord?id=CVE-2026-92010"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92010","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92010"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92010","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92010"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92010","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92010"}],"release_date":"2026-09-15T12:33:29.788000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component"},{"cve":"CVE-2026-92011","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"discovery_date":"2026-09-15T12:48:41.123329+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533753"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92011"},{"category":"external","summary":"RHBZ#2533753","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533753"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92011","url":"https://www.cve.org/CVERecord?id=CVE-2026-92011"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92011","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92011"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92011","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92011"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92011","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92011"}],"release_date":"2026-09-15T12:33:30.851000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component"},{"cve":"CVE-2026-92012","cwe":{"id":"CWE-266","name":"Incorrect Privilege Assignment"},"discovery_date":"2026-09-15T12:52:58.995110+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533769"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92012"},{"category":"external","summary":"RHBZ#2533769","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533769"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92012","url":"https://www.cve.org/CVERecord?id=CVE-2026-92012"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92012","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92012"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92012","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92012"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92012","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92012"}],"release_date":"2026-09-15T12:33:31.909000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component"},{"cve":"CVE-2026-92013","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"discovery_date":"2026-09-15T12:50:27.459983+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533762"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92013"},{"category":"external","summary":"RHBZ#2533762","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533762"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92013","url":"https://www.cve.org/CVERecord?id=CVE-2026-92013"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92013","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92013"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92013","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92013"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92013","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92013"}],"release_date":"2026-09-15T12:33:32.932000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component"},{"cve":"CVE-2026-92014","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"discovery_date":"2026-09-15T12:54:00.642463+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533771"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92014"},{"category":"external","summary":"RHBZ#2533771","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533771"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92014","url":"https://www.cve.org/CVERecord?id=CVE-2026-92014"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92014","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92014"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92014","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92014"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92014","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92014"}],"release_date":"2026-09-15T12:33:33.939000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component"},{"cve":"CVE-2026-92015","cwe":{"id":"CWE-266","name":"Incorrect Privilege Assignment"},"discovery_date":"2026-09-15T12:49:52.692625+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533760"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation in the WebExtensions component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation in the WebExtensions component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92015"},{"category":"external","summary":"RHBZ#2533760","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533760"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92015","url":"https://www.cve.org/CVERecord?id=CVE-2026-92015"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92015","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92015"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92015","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92015"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92015","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92015"}],"release_date":"2026-09-15T12:33:34.965000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation in the WebExtensions component"},{"cve":"CVE-2026-92016","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T12:51:05.456167+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533764"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the Disability Access APIs component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the Disability Access APIs component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92016"},{"category":"external","summary":"RHBZ#2533764","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533764"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92016","url":"https://www.cve.org/CVERecord?id=CVE-2026-92016"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92016","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92016"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92016","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92016"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92016","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92016"}],"release_date":"2026-09-15T12:33:35.999000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the Disability Access APIs component"},{"cve":"CVE-2026-92017","cwe":{"id":"CWE-266","name":"Incorrect Privilege Assignment"},"discovery_date":"2026-09-15T12:56:21.401738+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533779"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation in the DOM: Service Workers component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation in the DOM: Service Workers component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92017"},{"category":"external","summary":"RHBZ#2533779","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533779"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92017","url":"https://www.cve.org/CVERecord?id=CVE-2026-92017"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92017","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92017"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92017","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92017"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92017","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92017"}],"release_date":"2026-09-15T12:33:37.035000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation in the DOM: Service Workers component"},{"cve":"CVE-2026-92018","cwe":{"id":"CWE-791","name":"Incomplete Filtering of Special Elements"},"discovery_date":"2026-09-15T12:53:20.240091+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533773"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nSandbox escape in the DOM: Core & HTML component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92018"},{"category":"external","summary":"RHBZ#2533773","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533773"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92018","url":"https://www.cve.org/CVERecord?id=CVE-2026-92018"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92018","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92018"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92018","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92018"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92018","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92018"}],"release_date":"2026-09-15T12:33:38.091000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component"},{"cve":"CVE-2026-92019","cwe":{"id":"CWE-807","name":"Reliance on Untrusted Inputs in a Security Decision"},"discovery_date":"2026-09-15T12:44:13.484273+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533740"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nMitigation bypass in the Remote Settings Client component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Mitigation bypass in the Remote Settings Client component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92019"},{"category":"external","summary":"RHBZ#2533740","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533740"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92019","url":"https://www.cve.org/CVERecord?id=CVE-2026-92019"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92019","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92019"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92019","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92019"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92019","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92019"}],"release_date":"2026-09-15T12:33:39.132000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Mitigation bypass in the Remote Settings Client component"},{"cve":"CVE-2026-92020","cwe":{"id":"CWE-787","name":"Out-of-bounds Write"},"discovery_date":"2026-09-15T12:58:34.770127+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533786"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nPrivilege escalation due to incorrect boundary conditions in the Graphics: WebRender component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92020"},{"category":"external","summary":"RHBZ#2533786","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533786"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92020","url":"https://www.cve.org/CVERecord?id=CVE-2026-92020"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92020","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92020"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92020","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92020"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92020","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92020"}],"release_date":"2026-09-15T12:33:40.137000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component"},{"cve":"CVE-2026-92021","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T12:55:01.959339+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533774"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the JavaScript Engine: JIT component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92021"},{"category":"external","summary":"RHBZ#2533774","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533774"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92021","url":"https://www.cve.org/CVERecord?id=CVE-2026-92021"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92021","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92021"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92021","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92021"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92021","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92021"}],"release_date":"2026-09-15T12:33:41.163000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component"},{"cve":"CVE-2026-92022","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T12:52:18.043642+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533770"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the DOM: HTML Parser component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the DOM: HTML Parser component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92022"},{"category":"external","summary":"RHBZ#2533770","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533770"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92022","url":"https://www.cve.org/CVERecord?id=CVE-2026-92022"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92022","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92022"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92022","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92022"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92022","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92022"}],"release_date":"2026-09-15T12:33:42.587000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the DOM: HTML Parser component"},{"cve":"CVE-2026-92023","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T13:02:32.520737+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533799"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the XML component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the XML component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92023"},{"category":"external","summary":"RHBZ#2533799","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533799"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92023","url":"https://www.cve.org/CVERecord?id=CVE-2026-92023"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92023","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92023"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92023","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92023"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92023","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92023"}],"release_date":"2026-09-15T12:33:43.613000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the XML component"},{"cve":"CVE-2026-92024","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T12:42:52.299594+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533737"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the SVG component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the SVG component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92024"},{"category":"external","summary":"RHBZ#2533737","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533737"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92024","url":"https://www.cve.org/CVERecord?id=CVE-2026-92024"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92024","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92024"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92024","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92024"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92024","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92024"}],"release_date":"2026-09-15T12:33:44.665000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the SVG component"},{"cve":"CVE-2026-92025","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T13:00:48.700248+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533793"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the DOM: Navigation component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the DOM: Navigation component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92025"},{"category":"external","summary":"RHBZ#2533793","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533793"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92025","url":"https://www.cve.org/CVERecord?id=CVE-2026-92025"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92025","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92025"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92025","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92025"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92025","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92025"}],"release_date":"2026-09-15T12:33:45.712000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the DOM: Navigation component"},{"cve":"CVE-2026-92026","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T12:43:33.275615+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533741"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the Networking component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the Networking component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92026"},{"category":"external","summary":"RHBZ#2533741","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533741"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92026","url":"https://www.cve.org/CVERecord?id=CVE-2026-92026"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92026","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92026"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92026","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92026"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92026","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92026"}],"release_date":"2026-09-15T12:33:46.700000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the Networking component"},{"cve":"CVE-2026-92027","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T12:46:22.170590+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533757"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the DOM: Streams component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the DOM: Streams component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92027"},{"category":"external","summary":"RHBZ#2533757","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533757"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92027","url":"https://www.cve.org/CVERecord?id=CVE-2026-92027"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92027","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92027"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92027","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92027"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92027","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92027"}],"release_date":"2026-09-15T12:33:47.810000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the DOM: Streams component"},{"cve":"CVE-2026-92028","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T12:49:32.316908+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533758"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the DOM: Core & HTML component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the DOM: Core & HTML component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92028"},{"category":"external","summary":"RHBZ#2533758","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533758"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92028","url":"https://www.cve.org/CVERecord?id=CVE-2026-92028"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92028","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92028"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92028","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92028"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92028","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92028"}],"release_date":"2026-09-15T12:33:48.824000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the DOM: Core & HTML component"},{"cve":"CVE-2026-92029","cwe":{"id":"CWE-825","name":"Expired Pointer Dereference"},"discovery_date":"2026-09-15T13:02:11.980281+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533797"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nUse-after-free in the SVG component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Use-after-free in the SVG component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92029"},{"category":"external","summary":"RHBZ#2533797","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533797"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92029","url":"https://www.cve.org/CVERecord?id=CVE-2026-92029"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92029","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92029"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92029","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92029"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92029","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92029"}],"release_date":"2026-09-15T12:33:49.859000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Important"}],"title":"firefox: thunderbird: Use-after-free in the SVG component"},{"cve":"CVE-2026-92030","cwe":{"id":"CWE-807","name":"Reliance on Untrusted Inputs in a Security Decision"},"discovery_date":"2026-09-15T12:59:11.175898+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533791"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nMitigation bypass in the DOM: Copy & Paste and Drag & Drop component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92030"},{"category":"external","summary":"RHBZ#2533791","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533791"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92030","url":"https://www.cve.org/CVERecord?id=CVE-2026-92030"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92030","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92030"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92030","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92030"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92030","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92030"}],"release_date":"2026-09-15T12:33:50.891000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Moderate"}],"title":"firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component"},{"cve":"CVE-2026-92031","cwe":{"id":"CWE-497","name":"Exposure of Sensitive System Information to an Unauthorized Control Sphere"},"discovery_date":"2026-09-15T12:44:47.990509+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533742"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nInformation disclosure in the Graphics: ImageLib component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Information disclosure in the Graphics: ImageLib component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92031"},{"category":"external","summary":"RHBZ#2533742","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533742"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92031","url":"https://www.cve.org/CVERecord?id=CVE-2026-92031"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92031","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92031"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92031","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92031"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92031","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92031"}],"release_date":"2026-09-15T12:33:51.922000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Moderate"}],"title":"firefox: thunderbird: Information disclosure in the Graphics: ImageLib component"},{"cve":"CVE-2026-92032","cwe":{"id":"CWE-476","name":"NULL Pointer Dereference"},"discovery_date":"2026-09-15T12:45:07.307553+00:00","ids":[{"system_name":"Red Hat Bugzilla ID","text":"2533743"}],"notes":[{"category":"description","text":"A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:\nSandbox escape due to invalid pointer in the Graphics component","title":"Vulnerability description"},{"category":"summary","text":"firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component","title":"Vulnerability summary"},{"category":"other","text":"Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"fixed":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-92032"},{"category":"external","summary":"RHBZ#2533743","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533743"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-92032","url":"https://www.cve.org/CVERecord?id=CVE-2026-92032"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-92032","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92032"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92032","url":"https://www.mozilla.org/security/advisories/mfsa2026-92/#CVE-2026-92032"},{"category":"external","summary":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92032","url":"https://www.mozilla.org/security/advisories/mfsa2026-95/#CVE-2026-92032"}],"release_date":"2026-09-15T12:33:52.921000+00:00","remediations":[{"category":"vendor_fix","date":"2026-09-21T18:15:50+00:00","details":"For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258","product_ids":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"],"restart_required":{"category":"none"},"url":"https://access.redhat.com/errata/RHSA-2026:69461"}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.src","AppStream-10.2.Z:firefox-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debuginfo-0:140.16.0-1.el10_2.x86_64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.aarch64","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.ppc64le","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.s390x","AppStream-10.2.Z:firefox-debugsource-0:140.16.0-1.el10_2.x86_64"]}],"threats":[{"category":"impact","details":"Moderate"}],"title":"firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component"}]}