Bug 2489211 (CVE-2026-12327)
| Summary: | CVE-2026-12327 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | gotiwari, jhorak, mvyas, rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue:
Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-06-16 14:01:33 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:27717 https://access.redhat.com/errata/RHSA-2026:27717 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27733 https://access.redhat.com/errata/RHSA-2026:27733 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:27734 https://access.redhat.com/errata/RHSA-2026:27734 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:29940 https://access.redhat.com/errata/RHSA-2026:29940 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:30846 https://access.redhat.com/errata/RHSA-2026:30846 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:33445 https://access.redhat.com/errata/RHSA-2026:33445 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:36100 https://access.redhat.com/errata/RHSA-2026:36100 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:36102 https://access.redhat.com/errata/RHSA-2026:36102 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:36103 https://access.redhat.com/errata/RHSA-2026:36103 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:36101 https://access.redhat.com/errata/RHSA-2026:36101 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:37210 https://access.redhat.com/errata/RHSA-2026:37210 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:37391 https://access.redhat.com/errata/RHSA-2026:37391 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:38506 https://access.redhat.com/errata/RHSA-2026:38506 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:38751 https://access.redhat.com/errata/RHSA-2026:38751 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:38753 https://access.redhat.com/errata/RHSA-2026:38753 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:38750 https://access.redhat.com/errata/RHSA-2026:38750 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:39011 https://access.redhat.com/errata/RHSA-2026:39011 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:39141 https://access.redhat.com/errata/RHSA-2026:39141 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:39142 https://access.redhat.com/errata/RHSA-2026:39142 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:39428 https://access.redhat.com/errata/RHSA-2026:39428 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:39706 https://access.redhat.com/errata/RHSA-2026:39706 |