概述
Important: firefox security update
类型/严重性
Security Advisory: Important
标题
An update for firefox is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
描述
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.
Security Fix(es):
- firefox: Incorrect boundary conditions in the JavaScript Engine: JIT component (CVE-2026-8388)
- firefox: Other issue in the JavaScript Engine component (CVE-2026-8391)
- firefox: Sandbox escape in the Profile Backup component (CVE-2026-8401)
- firefox: Integer overflow in the Networking: JAR component (CVE-2026-8956)
- firefox: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 (CVE-2026-8975)
- firefox: Privilege escalation in the DOM: Workers component (CVE-2026-8955)
- firefox: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component (CVE-2026-8968)
- firefox: Incorrect boundary conditions, integer overflow in the Audio/Video component (CVE-2026-8954)
- firefox: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-8958)
- firefox: Incorrect boundary conditions in the Audio/Video: Web Codecs component (CVE-2026-8946)
- firefox: Privilege escalation in the Security component (CVE-2026-8970)
- firefox: Same-origin policy bypass in the Networking: HTTP component (CVE-2026-8950)
- firefox: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 (CVE-2026-8974)
- firefox: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-8953)
- firefox: Spoofing issue in the Form Autofill component (CVE-2026-8961)
- firefox: Use-after-free in the DOM: Bindings (WebIDL) component (CVE-2026-8947)
- firefox: Mitigation bypass in the DOM: Security component (CVE-2026-8962)
- firefox: Privilege escalation in the Enterprise Policies component (CVE-2026-8957)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
受影响的产品
-
Red Hat Enterprise Linux for x86_64 9 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 9 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x
-
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le
-
Red Hat Enterprise Linux for ARM 64 9 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x
修复
-
BZ - 2476469
- CVE-2026-8388 firefox: Incorrect boundary conditions in the JavaScript Engine: JIT component
-
BZ - 2476475
- CVE-2026-8391 firefox: Other issue in the JavaScript Engine component
-
BZ - 2476492
- CVE-2026-8401 firefox: Sandbox escape in the Profile Backup component
-
BZ - 2479839
- CVE-2026-8956 firefox: Integer overflow in the Networking: JAR component
-
BZ - 2479840
- CVE-2026-8975 firefox: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151
-
BZ - 2479842
- CVE-2026-8955 firefox: Privilege escalation in the DOM: Workers component
-
BZ - 2479846
- CVE-2026-8968 firefox: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
-
BZ - 2479847
- CVE-2026-8954 firefox: Incorrect boundary conditions, integer overflow in the Audio/Video component
-
BZ - 2479848
- CVE-2026-8958 firefox: Information disclosure, sandbox escape in the Security: Process Sandboxing component
-
BZ - 2479849
- CVE-2026-8946 firefox: Incorrect boundary conditions in the Audio/Video: Web Codecs component
-
BZ - 2479852
- CVE-2026-8970 firefox: Privilege escalation in the Security component
-
BZ - 2479853
- CVE-2026-8950 firefox: Same-origin policy bypass in the Networking: HTTP component
-
BZ - 2479855
- CVE-2026-8974 firefox: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151
-
BZ - 2479860
- CVE-2026-8953 firefox: Sandbox escape due to use-after-free in the Disability Access APIs component
-
BZ - 2479871
- CVE-2026-8961 firefox: Spoofing issue in the Form Autofill component
-
BZ - 2479873
- CVE-2026-8947 firefox: Use-after-free in the DOM: Bindings (WebIDL) component
-
BZ - 2479876
- CVE-2026-8962 firefox: Mitigation bypass in the DOM: Security component
-
BZ - 2479880
- CVE-2026-8957 firefox: Privilege escalation in the Enterprise Policies component
备注:
可能有这些软件包的更新版本。
点击软件包名称查看详情。
Red Hat Enterprise Linux for x86_64 9
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| x86_64 |
|
firefox-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: cbdc2044f00a10da4e33cdfe05283d0a3e516abb55497c66b9a3e473b7a9fd51 |
|
firefox-debuginfo-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: dc90174de915f28ec1b6025637c7977752b55a7798a25f2d110fc170095d41ce |
|
firefox-debugsource-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 35daa03f644bc606e17ff31e7ebe1928451f86732d3e6d2d1808bf652ec7edcd |
|
firefox-x11-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 62629b7e48594a1faabe3c62ab622368be0a8d9de5b02ba8fa11c56ead93bfc5 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| x86_64 |
|
firefox-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: cbdc2044f00a10da4e33cdfe05283d0a3e516abb55497c66b9a3e473b7a9fd51 |
|
firefox-debuginfo-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: dc90174de915f28ec1b6025637c7977752b55a7798a25f2d110fc170095d41ce |
|
firefox-debugsource-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 35daa03f644bc606e17ff31e7ebe1928451f86732d3e6d2d1808bf652ec7edcd |
|
firefox-x11-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 62629b7e48594a1faabe3c62ab622368be0a8d9de5b02ba8fa11c56ead93bfc5 |
Red Hat Enterprise Linux for IBM z Systems 9
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| s390x |
|
firefox-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: afc10aef6c99be903aad49097348ddfb77a6565201efd2c449a66b5aa3dfe4b2 |
|
firefox-debuginfo-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: f90703d7a3ad21dc29b404b725a8bb892f361bdfd2bc3fab6074ca086cd6c9bf |
|
firefox-debugsource-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 8a4d70f640a9f07a9f132a262d70a2211475f4c57f6d3c1776df4a1df3d55425 |
|
firefox-x11-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 13d15051bd4ee2237414238b934a2b649bb160e6125a8c48bc0ce42f4bea9788 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| s390x |
|
firefox-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: afc10aef6c99be903aad49097348ddfb77a6565201efd2c449a66b5aa3dfe4b2 |
|
firefox-debuginfo-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: f90703d7a3ad21dc29b404b725a8bb892f361bdfd2bc3fab6074ca086cd6c9bf |
|
firefox-debugsource-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 8a4d70f640a9f07a9f132a262d70a2211475f4c57f6d3c1776df4a1df3d55425 |
|
firefox-x11-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 13d15051bd4ee2237414238b934a2b649bb160e6125a8c48bc0ce42f4bea9788 |
Red Hat Enterprise Linux for Power, little endian 9
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| ppc64le |
|
firefox-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 29c81bedb4f1b6db34a35027bc15ad6803705d226664b2df0f0ba2b4aaff25e1 |
|
firefox-debuginfo-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 5529326c0ec8c8232851016dc5e477d4c9540e79387096159c9966d14d9479e5 |
|
firefox-debugsource-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: c691a26b7bb815a5d25dfcf71b2ac9c1c9dbae30fcbe50e18a29dac4d5d12600 |
|
firefox-x11-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: b571dc9cdaf67ac1c380758ba09c5f1fc7309c3b293ff8c3651f2825a45f9e2e |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| ppc64le |
|
firefox-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 29c81bedb4f1b6db34a35027bc15ad6803705d226664b2df0f0ba2b4aaff25e1 |
|
firefox-debuginfo-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 5529326c0ec8c8232851016dc5e477d4c9540e79387096159c9966d14d9479e5 |
|
firefox-debugsource-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: c691a26b7bb815a5d25dfcf71b2ac9c1c9dbae30fcbe50e18a29dac4d5d12600 |
|
firefox-x11-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: b571dc9cdaf67ac1c380758ba09c5f1fc7309c3b293ff8c3651f2825a45f9e2e |
Red Hat Enterprise Linux for ARM 64 9
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| aarch64 |
|
firefox-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 24d7b00289040a4546880fcb737492aba8c513ef2fefe6f7516569fdb60ecaa2 |
|
firefox-debuginfo-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: f8d9147cfd6597503ed2a6ccdb2b8ee192b6252492b22a30a6c2edc4f54b3e0d |
|
firefox-debugsource-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: cc99ff5f46dfd63be89401f77be4a7f9dde639643418a8712d41fd68e5532c2a |
|
firefox-x11-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 6589158092684eea890cfbfc7d350173c3a9e4eca694179640260c6b2c447ccd |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| aarch64 |
|
firefox-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 24d7b00289040a4546880fcb737492aba8c513ef2fefe6f7516569fdb60ecaa2 |
|
firefox-debuginfo-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: f8d9147cfd6597503ed2a6ccdb2b8ee192b6252492b22a30a6c2edc4f54b3e0d |
|
firefox-debugsource-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: cc99ff5f46dfd63be89401f77be4a7f9dde639643418a8712d41fd68e5532c2a |
|
firefox-x11-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 6589158092684eea890cfbfc7d350173c3a9e4eca694179640260c6b2c447ccd |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| ppc64le |
|
firefox-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 29c81bedb4f1b6db34a35027bc15ad6803705d226664b2df0f0ba2b4aaff25e1 |
|
firefox-debuginfo-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 5529326c0ec8c8232851016dc5e477d4c9540e79387096159c9966d14d9479e5 |
|
firefox-debugsource-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: c691a26b7bb815a5d25dfcf71b2ac9c1c9dbae30fcbe50e18a29dac4d5d12600 |
|
firefox-x11-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: b571dc9cdaf67ac1c380758ba09c5f1fc7309c3b293ff8c3651f2825a45f9e2e |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| x86_64 |
|
firefox-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: cbdc2044f00a10da4e33cdfe05283d0a3e516abb55497c66b9a3e473b7a9fd51 |
|
firefox-debuginfo-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: dc90174de915f28ec1b6025637c7977752b55a7798a25f2d110fc170095d41ce |
|
firefox-debugsource-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 35daa03f644bc606e17ff31e7ebe1928451f86732d3e6d2d1808bf652ec7edcd |
|
firefox-x11-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 62629b7e48594a1faabe3c62ab622368be0a8d9de5b02ba8fa11c56ead93bfc5 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| aarch64 |
|
firefox-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 24d7b00289040a4546880fcb737492aba8c513ef2fefe6f7516569fdb60ecaa2 |
|
firefox-debuginfo-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: f8d9147cfd6597503ed2a6ccdb2b8ee192b6252492b22a30a6c2edc4f54b3e0d |
|
firefox-debugsource-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: cc99ff5f46dfd63be89401f77be4a7f9dde639643418a8712d41fd68e5532c2a |
|
firefox-x11-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 6589158092684eea890cfbfc7d350173c3a9e4eca694179640260c6b2c447ccd |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| s390x |
|
firefox-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: afc10aef6c99be903aad49097348ddfb77a6565201efd2c449a66b5aa3dfe4b2 |
|
firefox-debuginfo-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: f90703d7a3ad21dc29b404b725a8bb892f361bdfd2bc3fab6074ca086cd6c9bf |
|
firefox-debugsource-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 8a4d70f640a9f07a9f132a262d70a2211475f4c57f6d3c1776df4a1df3d55425 |
|
firefox-x11-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 13d15051bd4ee2237414238b934a2b649bb160e6125a8c48bc0ce42f4bea9788 |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| x86_64 |
|
firefox-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: cbdc2044f00a10da4e33cdfe05283d0a3e516abb55497c66b9a3e473b7a9fd51 |
|
firefox-debuginfo-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: dc90174de915f28ec1b6025637c7977752b55a7798a25f2d110fc170095d41ce |
|
firefox-debugsource-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 35daa03f644bc606e17ff31e7ebe1928451f86732d3e6d2d1808bf652ec7edcd |
|
firefox-x11-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 62629b7e48594a1faabe3c62ab622368be0a8d9de5b02ba8fa11c56ead93bfc5 |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| aarch64 |
|
firefox-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 24d7b00289040a4546880fcb737492aba8c513ef2fefe6f7516569fdb60ecaa2 |
|
firefox-debuginfo-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: f8d9147cfd6597503ed2a6ccdb2b8ee192b6252492b22a30a6c2edc4f54b3e0d |
|
firefox-debugsource-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: cc99ff5f46dfd63be89401f77be4a7f9dde639643418a8712d41fd68e5532c2a |
|
firefox-x11-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 6589158092684eea890cfbfc7d350173c3a9e4eca694179640260c6b2c447ccd |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| ppc64le |
|
firefox-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 29c81bedb4f1b6db34a35027bc15ad6803705d226664b2df0f0ba2b4aaff25e1 |
|
firefox-debuginfo-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 5529326c0ec8c8232851016dc5e477d4c9540e79387096159c9966d14d9479e5 |
|
firefox-debugsource-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: c691a26b7bb815a5d25dfcf71b2ac9c1c9dbae30fcbe50e18a29dac4d5d12600 |
|
firefox-x11-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: b571dc9cdaf67ac1c380758ba09c5f1fc7309c3b293ff8c3651f2825a45f9e2e |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8
| SRPM |
|
firefox-140.11.0-1.el9_8.src.rpm
|
SHA-256: 71b3fe91f8061197ce1a7f8da01acf7f16bf2e5bed4315be53bd00983aeb6afc |
| s390x |
|
firefox-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: afc10aef6c99be903aad49097348ddfb77a6565201efd2c449a66b5aa3dfe4b2 |
|
firefox-debuginfo-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: f90703d7a3ad21dc29b404b725a8bb892f361bdfd2bc3fab6074ca086cd6c9bf |
|
firefox-debugsource-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 8a4d70f640a9f07a9f132a262d70a2211475f4c57f6d3c1776df4a1df3d55425 |
|
firefox-x11-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 13d15051bd4ee2237414238b934a2b649bb160e6125a8c48bc0ce42f4bea9788 |