ALSA-2026:71652

See a problem?
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:71652.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALSA-2026:71652
Related
Published
2026-09-24T00:00:00Z
Modified
2026-09-25T15:11:45Z
Summary
Important: firefox security update
Details

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

  • firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)
  • firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)
  • firefox: thunderbird: Use-after-free in the Networking component (CVE-2026-92026)
  • firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-92031)
  • firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component (CVE-2026-92032)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92010)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92006)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92011)
  • firefox: thunderbird: Use-after-free in the DOM: Streams component (CVE-2026-92027)
  • firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-92028)
  • firefox: thunderbird: Privilege escalation in the WebExtensions component (CVE-2026-92015)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92013)
  • firefox: thunderbird: Use-after-free in the Disability Access APIs component (CVE-2026-92016)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92012)
  • firefox: thunderbird: Use-after-free in the DOM: HTML Parser component (CVE-2026-92022)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component (CVE-2026-92014)
  • firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component (CVE-2026-92018)
  • firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component (CVE-2026-92021)
  • firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component (CVE-2026-92005)
  • firefox: thunderbird: Privilege escalation in the DOM: Service Workers component (CVE-2026-92017)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92009)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component (CVE-2026-92020)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92008)
  • firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component (CVE-2026-92030)
  • firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92007)
  • firefox: thunderbird: Use-after-free in the DOM: Navigation component (CVE-2026-92025)
  • firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92029)
  • firefox: thunderbird: Use-after-free in the XML component (CVE-2026-92023)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8 / firefox

Package

Name
firefox
Purl
pkg:rpm/almalinux/firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
140.16.0-1.el8_10.alma.1

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:71652.json"