Bug 2503440 (CVE-2026-16361)

Summary: CVE-2026-16361 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: gotiwari, jhorak, mvyas, rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-21 13:02:26 UTC
Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38 and Firefox ESR 140.13.

Comment 1 errata-xmlrpc 2026-07-28 16:10:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:47101 https://access.redhat.com/errata/RHSA-2026:47101

Comment 2 errata-xmlrpc 2026-07-28 21:14:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:47105 https://access.redhat.com/errata/RHSA-2026:47105

Comment 3 errata-xmlrpc 2026-07-29 01:39:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:47104 https://access.redhat.com/errata/RHSA-2026:47104

Comment 4 errata-xmlrpc 2026-08-03 10:23:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:49621 https://access.redhat.com/errata/RHSA-2026:49621

Comment 5 errata-xmlrpc 2026-08-04 08:44:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:49922 https://access.redhat.com/errata/RHSA-2026:49922

Comment 6 errata-xmlrpc 2026-08-04 08:59:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:49921 https://access.redhat.com/errata/RHSA-2026:49921

Comment 7 errata-xmlrpc 2026-08-11 13:03:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:53445 https://access.redhat.com/errata/RHSA-2026:53445

Comment 8 errata-xmlrpc 2026-08-11 13:44:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:53444 https://access.redhat.com/errata/RHSA-2026:53444

Comment 9 errata-xmlrpc 2026-08-11 13:45:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:53446 https://access.redhat.com/errata/RHSA-2026:53446

Comment 10 errata-xmlrpc 2026-08-11 13:58:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:53455 https://access.redhat.com/errata/RHSA-2026:53455

Comment 11 errata-xmlrpc 2026-08-11 14:21:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:53453 https://access.redhat.com/errata/RHSA-2026:53453

Comment 12 errata-xmlrpc 2026-08-11 14:22:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:53454 https://access.redhat.com/errata/RHSA-2026:53454

Comment 13 errata-xmlrpc 2026-08-11 14:30:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:53475 https://access.redhat.com/errata/RHSA-2026:53475

Comment 14 errata-xmlrpc 2026-08-12 06:59:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:54180 https://access.redhat.com/errata/RHSA-2026:54180

Comment 15 errata-xmlrpc 2026-08-12 07:04:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:54185 https://access.redhat.com/errata/RHSA-2026:54185

Comment 16 errata-xmlrpc 2026-08-12 07:13:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:54182 https://access.redhat.com/errata/RHSA-2026:54182

Comment 17 errata-xmlrpc 2026-08-12 07:14:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:54181 https://access.redhat.com/errata/RHSA-2026:54181

Comment 18 errata-xmlrpc 2026-08-12 09:45:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:54259 https://access.redhat.com/errata/RHSA-2026:54259

Comment 19 errata-xmlrpc 2026-08-12 09:57:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:54249 https://access.redhat.com/errata/RHSA-2026:54249

Comment 20 errata-xmlrpc 2026-08-12 10:18:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:54248 https://access.redhat.com/errata/RHSA-2026:54248

Comment 21 errata-xmlrpc 2026-08-12 12:59:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:54339 https://access.redhat.com/errata/RHSA-2026:54339