Bug 2455897 (CVE-2026-5734)
| Summary: | CVE-2026-5734 thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | gotiwari, jgrulich, jhorak, mvyas, rhel-process-autobot, tpopela, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-04-07 13:01:25 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:7672 https://access.redhat.com/errata/RHSA-2026:7672 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:7671 https://access.redhat.com/errata/RHSA-2026:7671 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8052 https://access.redhat.com/errata/RHSA-2026:8052 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8459 https://access.redhat.com/errata/RHSA-2026:8459 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:9345 https://access.redhat.com/errata/RHSA-2026:9345 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:9638 https://access.redhat.com/errata/RHSA-2026:9638 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:11805 https://access.redhat.com/errata/RHSA-2026:11805 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:11813 https://access.redhat.com/errata/RHSA-2026:11813 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:12264 https://access.redhat.com/errata/RHSA-2026:12264 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:13342 https://access.redhat.com/errata/RHSA-2026:13342 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:13412 https://access.redhat.com/errata/RHSA-2026:13412 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:13533 https://access.redhat.com/errata/RHSA-2026:13533 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:13596 https://access.redhat.com/errata/RHSA-2026:13596 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:13582 https://access.redhat.com/errata/RHSA-2026:13582 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:13583 https://access.redhat.com/errata/RHSA-2026:13583 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:13600 https://access.redhat.com/errata/RHSA-2026:13600 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:13665 https://access.redhat.com/errata/RHSA-2026:13665 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:13682 https://access.redhat.com/errata/RHSA-2026:13682 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:13683 https://access.redhat.com/errata/RHSA-2026:13683 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:13922 https://access.redhat.com/errata/RHSA-2026:13922 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:13977 https://access.redhat.com/errata/RHSA-2026:13977 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:14223 https://access.redhat.com/errata/RHSA-2026:14223 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:14303 https://access.redhat.com/errata/RHSA-2026:14303 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:15889 https://access.redhat.com/errata/RHSA-2026:15889 |