rlsa-2026:69461
CVSS 7.5 osv_rockyMozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): * firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024) * firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019) * firefox: thunderbird: Use-after-free in the Networking component (CVE-2026-92026) * firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-92031) * firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component (CVE-2026-92032) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92010) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92006) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92011) * firefox: thunderbird: Use-after-free in the DOM: Streams component (CVE-2026-92027) * firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-92028) * firefox: thunderbird: Privilege escalation in the WebExtensions component (CVE-2026-92015) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92013) * firefox: thunderbird: Use-after-free in the Disability Access APIs component (CVE-2026-92016) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92012) * firefox: thunderbird: Use-after-free in the DOM: HTML Parser component (CVE-2026-92022) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component (CVE-2026-92014) * firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component (CVE-2026-92018) * firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component (CVE-2026-92021) * firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component (CVE-2026-92005) * firefox: thunderbird: Privilege escalation in the DOM: Service Workers component (CVE-2026-92017) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92009) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component (CVE-2026-92020) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92008) * firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component (CVE-2026-92030) * firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92007) * firefox: thunderbird: Use-after-free in the DOM: Navigation component (CVE-2026-92025) * firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92029) * firefox: thunderbird: Use-after-free in the XML component (CVE-2026-92023) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
- https://errata.rockylinux.org/RLSA-2026:69461
- https://bugzilla.redhat.com/show_bug.cgi?id=2533737
- https://bugzilla.redhat.com/show_bug.cgi?id=2533740
- https://bugzilla.redhat.com/show_bug.cgi?id=2533741
- https://bugzilla.redhat.com/show_bug.cgi?id=2533742
- https://bugzilla.redhat.com/show_bug.cgi?id=2533743
- https://bugzilla.redhat.com/show_bug.cgi?id=2533747
- https://bugzilla.redhat.com/show_bug.cgi?id=2533751
- https://bugzilla.redhat.com/show_bug.cgi?id=2533753
- https://bugzilla.redhat.com/show_bug.cgi?id=2533757
- https://bugzilla.redhat.com/show_bug.cgi?id=2533758
- https://bugzilla.redhat.com/show_bug.cgi?id=2533760
- https://bugzilla.redhat.com/show_bug.cgi?id=2533762
- https://bugzilla.redhat.com/show_bug.cgi?id=2533764
- https://bugzilla.redhat.com/show_bug.cgi?id=2533769
- https://bugzilla.redhat.com/show_bug.cgi?id=2533770
- https://bugzilla.redhat.com/show_bug.cgi?id=2533771
- https://bugzilla.redhat.com/show_bug.cgi?id=2533773
- https://bugzilla.redhat.com/show_bug.cgi?id=2533774
- https://bugzilla.redhat.com/show_bug.cgi?id=2533778
- https://bugzilla.redhat.com/show_bug.cgi?id=2533779
- https://bugzilla.redhat.com/show_bug.cgi?id=2533781
- https://bugzilla.redhat.com/show_bug.cgi?id=2533786
- https://bugzilla.redhat.com/show_bug.cgi?id=2533790
- https://bugzilla.redhat.com/show_bug.cgi?id=2533791
- https://bugzilla.redhat.com/show_bug.cgi?id=2533792
- https://bugzilla.redhat.com/show_bug.cgi?id=2533793
- https://bugzilla.redhat.com/show_bug.cgi?id=2533797
- https://bugzilla.redhat.com/show_bug.cgi?id=2533799
- https://access.redhat.com/errata/RHSA-2026:69461
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"source": "https://storage.googleapis.com/resf-osv-data/RLSA-2026:69461.json"
},
"package": {
"ecosystem": "Rocky Linux:10",
"name": "firefox",
"purl": "pkg:rpm/rocky-linux/firefox?distro=rocky-linux-10&epoch=0"
},
"ranges": [
{
"database_specific": {
"yum_repository": "AppStream"
},
"events": [
{
"introduced": "0"
},
{
"fixed": "0:140.16.0-1.el10_2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"credits": [
{
"name": "Rocky Enterprise Software Foundation"
},
{
"name": "Red Hat"
}
],
"database_specific": {
"license": "CC-BY-4.0",
"license_url": "https://creativecommons.org/licenses/by/4.0/",
"source_advisory": "RHSA-2026:69461"
},
"details": "Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.\n\nSecurity Fix(es):\n\n* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)\n\n* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)\n\n* firefox: thunderbird: Use-after-free in the Networking component (CVE-2026-92026)\n\n* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-92031)\n\n* firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component (CVE-2026-92032)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92010)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92006)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92011)\n\n* firefox: thunderbird: Use-after-free in the DOM: Streams component (CVE-2026-92027)\n\n* firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-92028)\n\n* firefox: thunderbird: Privilege escalation in the WebExtensions component (CVE-2026-92015)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92013)\n\n* firefox: thunderbird: Use-after-free in the Disability Access APIs component (CVE-2026-92016)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92012)\n\n* firefox: thunderbird: Use-after-free in the DOM: HTML Parser component (CVE-2026-92022)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component (CVE-2026-92014)\n\n* firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component (CVE-2026-92018)\n\n* firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component (CVE-2026-92021)\n\n* firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component (CVE-2026-92005)\n\n* firefox: thunderbird: Privilege escalation in the DOM: Service Workers component (CVE-2026-92017)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92009)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component (CVE-2026-92020)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92008)\n\n* firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component (CVE-2026-92030)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92007)\n\n* firefox: thunderbird: Use-after-free in the DOM: Navigation component (CVE-2026-92025)\n\n* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92029)\n\n* firefox: thunderbird: Use-after-free in the XML component (CVE-2026-92023)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.",
"id": "RLSA-2026:69461",
"modified": "2026-09-22T12:30:02.631378257Z",
"published": "2026-09-22T12:08:07.529031Z",
"references": [
{
"type": "ADVISORY",
"url": "https://errata.rockylinux.org/RLSA-2026:69461"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533737"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533740"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533741"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533742"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533743"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533747"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533751"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533753"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533757"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533758"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533760"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533762"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533764"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533769"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533770"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533771"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533773"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533774"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533778"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533779"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533781"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533786"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533790"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533791"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533792"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533793"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533797"
},
{
"type": "REPORT",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2533799"
},
{
"type": "ADVISORY",
"url": "https://access.redhat.com/errata/RHSA-2026:69461"
}
],
"schema_version": "1.9.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Important: firefox security update",
"upstream": [
"CVE-2026-92005",
"CVE-2026-92006",
"CVE-2026-92007",
"CVE-2026-92008",
"CVE-2026-92009",
"CVE-2026-92010",
"CVE-2026-92011",
"CVE-2026-92012",
"CVE-2026-92013",
"CVE-2026-92014",
"CVE-2026-92015",
"CVE-2026-92016",
"CVE-2026-92017",
"CVE-2026-92018",
"CVE-2026-92019",
"CVE-2026-92020",
"CVE-2026-92021",
"CVE-2026-92022",
"CVE-2026-92023",
"CVE-2026-92024",
"CVE-2026-92025",
"CVE-2026-92026",
"CVE-2026-92027",
"CVE-2026-92028",
"CVE-2026-92029",
"CVE-2026-92030",
"CVE-2026-92031",
"CVE-2026-92032"
]
}