Bug 2479840 (CVE-2026-8975)

Summary: CVE-2026-8975 firefox: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gotiwari, jgrulich, jhorak, mvyas, rhel-process-autobot, tpopela, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-19 14:01:45 UTC
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.

Comment 1 errata-xmlrpc 2026-05-27 16:01:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:21382 https://access.redhat.com/errata/RHSA-2026:21382

Comment 2 errata-xmlrpc 2026-05-27 16:05:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:21380 https://access.redhat.com/errata/RHSA-2026:21380

Comment 3 errata-xmlrpc 2026-05-27 16:07:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:21381 https://access.redhat.com/errata/RHSA-2026:21381

Comment 4 errata-xmlrpc 2026-05-27 16:41:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:21378 https://access.redhat.com/errata/RHSA-2026:21378

Comment 5 errata-xmlrpc 2026-06-01 15:28:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:22325 https://access.redhat.com/errata/RHSA-2026:22325

Comment 6 errata-xmlrpc 2026-06-03 00:49:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:22643 https://access.redhat.com/errata/RHSA-2026:22643

Comment 8 errata-xmlrpc 2026-06-16 06:06:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:26174 https://access.redhat.com/errata/RHSA-2026:26174

Comment 9 errata-xmlrpc 2026-06-16 11:59:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:26269 https://access.redhat.com/errata/RHSA-2026:26269

Comment 10 errata-xmlrpc 2026-06-16 11:59:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:26270 https://access.redhat.com/errata/RHSA-2026:26270

Comment 11 errata-xmlrpc 2026-06-16 12:17:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:26268 https://access.redhat.com/errata/RHSA-2026:26268

Comment 12 errata-xmlrpc 2026-06-17 05:42:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:26491 https://access.redhat.com/errata/RHSA-2026:26491

Comment 13 errata-xmlrpc 2026-06-17 05:51:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:26493 https://access.redhat.com/errata/RHSA-2026:26493

Comment 14 errata-xmlrpc 2026-06-17 05:57:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:26492 https://access.redhat.com/errata/RHSA-2026:26492

Comment 15 errata-xmlrpc 2026-06-17 08:02:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:26521 https://access.redhat.com/errata/RHSA-2026:26521

Comment 16 errata-xmlrpc 2026-06-17 10:00:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:26536 https://access.redhat.com/errata/RHSA-2026:26536

Comment 17 errata-xmlrpc 2026-06-17 10:24:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:26539 https://access.redhat.com/errata/RHSA-2026:26539

Comment 18 errata-xmlrpc 2026-06-17 10:56:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:26551 https://access.redhat.com/errata/RHSA-2026:26551

Comment 19 errata-xmlrpc 2026-06-17 14:34:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:26606 https://access.redhat.com/errata/RHSA-2026:26606

Comment 20 errata-xmlrpc 2026-06-17 15:21:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:26629 https://access.redhat.com/errata/RHSA-2026:26629

Comment 21 errata-xmlrpc 2026-06-17 15:39:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:26630 https://access.redhat.com/errata/RHSA-2026:26630

Comment 22 errata-xmlrpc 2026-06-22 02:29:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:27715 https://access.redhat.com/errata/RHSA-2026:27715