Bug 2428963 (CVE-2026-0891)
| Summary: | CVE-2026-0891 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | gotiwari, jgrulich, jhorak, mvyas, tpopela |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-01-13 14:01:50 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:0667 https://access.redhat.com/errata/RHSA-2026:0667 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:0694 https://access.redhat.com/errata/RHSA-2026:0694 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:0924 https://access.redhat.com/errata/RHSA-2026:0924 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1320 https://access.redhat.com/errata/RHSA-2026:1320 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:1413 https://access.redhat.com/errata/RHSA-2026:1413 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:1415 https://access.redhat.com/errata/RHSA-2026:1415 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1414 https://access.redhat.com/errata/RHSA-2026:1414 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:1461 https://access.redhat.com/errata/RHSA-2026:1461 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:1462 https://access.redhat.com/errata/RHSA-2026:1462 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:1471 https://access.redhat.com/errata/RHSA-2026:1471 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:1487 https://access.redhat.com/errata/RHSA-2026:1487 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:2041 https://access.redhat.com/errata/RHSA-2026:2041 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:2044 https://access.redhat.com/errata/RHSA-2026:2044 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:2047 https://access.redhat.com/errata/RHSA-2026:2047 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:2043 https://access.redhat.com/errata/RHSA-2026:2043 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:2069 https://access.redhat.com/errata/RHSA-2026:2069 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:2070 https://access.redhat.com/errata/RHSA-2026:2070 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:2073 https://access.redhat.com/errata/RHSA-2026:2073 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:2074 https://access.redhat.com/errata/RHSA-2026:2074 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:2231 https://access.redhat.com/errata/RHSA-2026:2231 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:2220 https://access.redhat.com/errata/RHSA-2026:2220 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Red Hat Enterprise Linux 10 Via RHSA-2026:2271 https://access.redhat.com/errata/RHSA-2026:2271 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Red Hat Enterprise Linux 10 Via RHSA-2026:2286 https://access.redhat.com/errata/RHSA-2026:2286 |