{"schema_version": "1.7.0", "id": "RLSA-2026:47101", "modified": "2026-07-30T12:08:52.563913Z", "published": "2026-07-30T12:06:30.380063Z", "upstream": ["CVE-2026-15718", "CVE-2026-15719", "CVE-2026-16349", "CVE-2026-16350", "CVE-2026-16351", "CVE-2026-16352", "CVE-2026-16353", "CVE-2026-16354", "CVE-2026-16355", "CVE-2026-16356", "CVE-2026-16357", "CVE-2026-16358", "CVE-2026-16359", "CVE-2026-16360", "CVE-2026-16361", "CVE-2026-16362", "CVE-2026-16363", "CVE-2026-16368", "CVE-2026-16369", "CVE-2026-16371", "CVE-2026-16374", "CVE-2026-16375", "CVE-2026-16377", "CVE-2026-16379", "CVE-2026-16381", "CVE-2026-16383", "CVE-2026-16387", "CVE-2026-16390", "CVE-2026-16391", "CVE-2026-16396", "CVE-2026-16405", "CVE-2026-16412"], "summary": "Important: firefox security update", "details": "Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.\n\nSecurity Fix(es):\n\n* firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719)\n\n* firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718)\n\n* firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390)\n\n* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350)\n\n* firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391)\n\n* firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375)\n\n* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356)\n\n* firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363)\n\n* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412)\n\n* firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381)\n\n* firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355)\n\n* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361)\n\n* firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352)\n\n* firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368)\n\n* firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377)\n\n* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360)\n\n* firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362)\n\n* firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358)\n\n* firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387)\n\n* firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349)\n\n* firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357)\n\n* firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351)\n\n* firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371)\n\n* firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379)\n\n* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354)\n\n* firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374)\n\n* firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359)\n\n* firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383)\n\n* firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369)\n\n* firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353)\n\n* firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396)\n\n* firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:10", "name": "firefox", "purl": "pkg:rpm/rocky-linux/firefox?distro=rocky-linux-10&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:140.13.0-1.el10_2"}], "database_specific": {"yum_repository": "AppStream"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2026:47101"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503432"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503501"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503473"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503472"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503456"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503423"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503425"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503497"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503430"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503451"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503440"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503463"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503517"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503489"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503505"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503439"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503513"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503444"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499974"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503434"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503454"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503420"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503416"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2499973"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503527"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503521"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503491"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503512"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503500"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503498"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503415"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2503485"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}