Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:7671 - Security Advisory
Issued:
2026-04-13
Updated:
2026-04-13

RHSA-2026:7671 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: firefox security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for firefox is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

  • libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416)
  • libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636)
  • thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (CVE-2026-5734)
  • thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (CVE-2026-5731)
  • firefox: thunderbird: Incorrect boundary conditions, integer overflow in the Graphics: Text component (CVE-2026-5732)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2451805 - CVE-2026-33416 libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
  • BZ - 2451819 - CVE-2026-33636 libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
  • BZ - 2455897 - CVE-2026-5734 thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
  • BZ - 2455901 - CVE-2026-5731 thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
  • BZ - 2455908 - CVE-2026-5732 firefox: thunderbird: Incorrect boundary conditions, integer overflow in the Graphics: Text component

CVEs

  • CVE-2026-5731
  • CVE-2026-5732
  • CVE-2026-5734
  • CVE-2026-33416
  • CVE-2026-33636

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
firefox-140.9.1-1.el9_7.src.rpm SHA-256: e11d8836acab56e7ec68cb99803c4b6fa62c851eb8d9893eb8df1ba3f0e22805
x86_64
firefox-140.9.1-1.el9_7.x86_64.rpm SHA-256: 0165db83f7bd801b10a97381459548eee6f024b4f170fe7ea9d1e66ef1e84162
firefox-debuginfo-140.9.1-1.el9_7.x86_64.rpm SHA-256: 79b84e1f6b0271e4a1c96fe9a8b663a10924ce9462a0d5eafebd1215791ae1da
firefox-debugsource-140.9.1-1.el9_7.x86_64.rpm SHA-256: 1eccd655df9d10d3c3597c812de0f57004a24034041c11257def475ce01ae511
firefox-x11-140.9.1-1.el9_7.x86_64.rpm SHA-256: d44c8f20fd43cd289062f8fbee857646025131e4a3f2ee3c1b4bae00d5d096ee

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
firefox-140.9.1-1.el9_7.src.rpm SHA-256: e11d8836acab56e7ec68cb99803c4b6fa62c851eb8d9893eb8df1ba3f0e22805
s390x
firefox-140.9.1-1.el9_7.s390x.rpm SHA-256: 6eaff3269b53ff933e1136f414e4b021635b3e1d462d35ab4ec4989c9c6991df
firefox-debuginfo-140.9.1-1.el9_7.s390x.rpm SHA-256: 8b3e64c1ac6c976489b5cc020f3d6c167df08f525bd326542bc744f56d71c618
firefox-debugsource-140.9.1-1.el9_7.s390x.rpm SHA-256: 498b47c85851100822b29cf7e850d92ea36b8b476f05ec56626b80e52ba326b0
firefox-x11-140.9.1-1.el9_7.s390x.rpm SHA-256: b112d8db3c09df2bbfe7a84a88bd928873e0b8be4f715d28f7eaa846f7c0292b

Red Hat Enterprise Linux for Power, little endian 9

SRPM
firefox-140.9.1-1.el9_7.src.rpm SHA-256: e11d8836acab56e7ec68cb99803c4b6fa62c851eb8d9893eb8df1ba3f0e22805
ppc64le
firefox-140.9.1-1.el9_7.ppc64le.rpm SHA-256: e978bc4a455db3275fa0eb0e88830a0a2a173963b47947bb86999c9f1d34da3d
firefox-debuginfo-140.9.1-1.el9_7.ppc64le.rpm SHA-256: b0ed38ae30f8c81f15eea297c5d0b8caa4b5b112a77ce47e8dca9dff0cb99287
firefox-debugsource-140.9.1-1.el9_7.ppc64le.rpm SHA-256: 2c24f323e7bde7477f97d5254714447abc176814a74108f5c3e46b6de36d33d0
firefox-x11-140.9.1-1.el9_7.ppc64le.rpm SHA-256: 3259852e412bce9b9f353fd4f0fab956784ddeed4c7d44f1c3220ab1ccab0516

Red Hat Enterprise Linux for ARM 64 9

SRPM
firefox-140.9.1-1.el9_7.src.rpm SHA-256: e11d8836acab56e7ec68cb99803c4b6fa62c851eb8d9893eb8df1ba3f0e22805
aarch64
firefox-140.9.1-1.el9_7.aarch64.rpm SHA-256: 48888a5a46e6c92a2c6039d57301bc6ba409590d104a2e22bced98c6d9e99d7a
firefox-debuginfo-140.9.1-1.el9_7.aarch64.rpm SHA-256: 888151c3476c5cdf024600de26251ebeb6706d474b1049fdbabeac7e4498c812
firefox-debugsource-140.9.1-1.el9_7.aarch64.rpm SHA-256: 8d1d10082660a6b0434c8c16a344586dfdae2287389ae9490bc5d7cc84aeb240
firefox-x11-140.9.1-1.el9_7.aarch64.rpm SHA-256: d13b9057105e54a746c1bc6dce29b45ecb2d9d0eafffca515a707e7ba5c86577

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility