{"schema_version": "1.7.0", "id": "RLSA-2026:58898", "modified": "2026-08-25T06:09:28.844985Z", "published": "2026-08-25T06:01:14.220590Z", "upstream": ["CVE-2026-74934", "CVE-2026-74935", "CVE-2026-74936", "CVE-2026-74939", "CVE-2026-74940", "CVE-2026-74941", "CVE-2026-74942", "CVE-2026-74943", "CVE-2026-74944", "CVE-2026-74945", "CVE-2026-74946", "CVE-2026-74948", "CVE-2026-74949", "CVE-2026-74953", "CVE-2026-74957", "CVE-2026-74959", "CVE-2026-74960", "CVE-2026-74962", "CVE-2026-74963", "CVE-2026-74964", "CVE-2026-74965", "CVE-2026-74967", "CVE-2026-74969", "CVE-2026-74971", "CVE-2026-74972", "CVE-2026-74973", "CVE-2026-74974", "CVE-2026-74976", "CVE-2026-74983", "CVE-2026-74987", "CVE-2026-74990"], "summary": "Important: firefox security update", "details": "Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.\n\nSecurity Fix(es):\n\n* firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component (CVE-2026-74983)\n\n* firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934)\n\n* firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953)\n\n* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987)\n\n* firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948)\n\n* firefox: thunderbird: Use-after-free in the Graphics: ImageLib component (CVE-2026-74943)\n\n* firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component (CVE-2026-74971)\n\n* firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941)\n\n* firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965)\n\n* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946)\n\n* firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973)\n\n* firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (CVE-2026-74949)\n\n* firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74990)\n\n* firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component (CVE-2026-74936)\n\n* firefox: thunderbird: Use-after-free in the Graphics: Text component (CVE-2026-74940)\n\n* firefox: thunderbird: Site isolation issue in the WebExtensions component (CVE-2026-74960)\n\n* firefox: thunderbird: Use-after-free in the Layout: Text and Fonts component (CVE-2026-74969)\n\n* firefox: thunderbird: Mitigation bypass in the Storage: Cache API component (CVE-2026-74959)\n\n* firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-74976)\n\n* firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component (CVE-2026-74974)\n\n* firefox: thunderbird: Mitigation bypass in the Safe Browsing component (CVE-2026-74957)\n\n* firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component (CVE-2026-74967)\n\n* firefox: Privilege escalation in the Remote Settings Client component (CVE-2026-74942)\n\n* firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-74939)\n\n* firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component (CVE-2026-74972)\n\n* firefox: thunderbird: Information disclosure in the Graphics: Text component (CVE-2026-74945)\n\n* firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-74963)\n\n* firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-74944)\n\n* firefox: Integer overflow in the Graphics component (CVE-2026-74964)\n\n* firefox: Site isolation issue in the Networking: Cookies component (CVE-2026-74962)\n\n* firefox: thunderbird: Privilege escalation in the DOM: Networking component (CVE-2026-74935)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:8", "name": "firefox", "purl": "pkg:rpm/rocky-linux/firefox?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:140.14.0-1.el8_10"}], "database_specific": {"yum_repository": "AppStream"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2026:58898"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517819"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517820"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517822"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517823"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517825"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517826"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517831"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517833"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517834"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517835"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517836"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517837"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517839"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517840"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517841"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517845"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517846"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517849"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517851"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517853"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517856"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517858"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517859"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517860"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517862"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517863"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517866"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517868"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517870"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517872"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2517874"}, {"type": "ADVISORY", "url": "https://access.redhat.com/errata/RHSA-2026:58898"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}], "database_specific": {"license": "CC-BY-4.0", "license_url": "https://creativecommons.org/licenses/by/4.0/", "source_advisory": "RHSA-2026:58898"}}