Skip to main content
EPSS 0.6%top 53%

Libvpx: Vulnerability in Mozilla Firefox (CVE-2026-2447)

0
High
Published: 02/16/2026 (02/16/2026, 14:13:23 UTC)
Source: GCVE Database
Vendor/Project: Mozilla
Product: Firefox

Description

A security update for Mozilla Firefox and related components addresses multiple vulnerabilities including heap buffer overflow, use-after-free, integer overflows, sandbox escapes, privilege escalations, mitigation bypasses, and information disclosure issues. These vulnerabilities affect various Firefox components such as the JavaScript engine, DOM, Audio/Video, Networking, Graphics, and Storage. The update is provided by Red Hat for Firefox versions distributed with Red Hat Enterprise Linux 9.2 and related products. The advisory rates the security impact as Important (high severity).

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

redhat/libvpx
pkg:rpm/redhat/libvpx
Affected versions
>=9.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 15:56:03 UTC

Technical Analysis

CVE-2026-2447 describes a heap buffer overflow vulnerability in the libvpx component used by Mozilla Firefox and Thunderbird. The vulnerability allows for potential memory corruption leading to high impact on confidentiality, integrity, and availability. Mozilla fixed this issue in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2. The vulnerability has a CVSS 3.1 base score of 8.8, indicating high severity. Exploitation via Thunderbird email is generally mitigated by disabled scripting, but browser contexts remain vulnerable if unpatched.

Potential Impact

Successful exploitation of this heap buffer overflow can result in complete compromise of confidentiality, integrity, and availability of the affected application. The vulnerability is rated high severity with a CVSS score of 8.8. While Thunderbird's default email reading context mitigates exploitation risk due to disabled scripting, Firefox and browser-like contexts remain at risk if unpatched.

Mitigation Recommendations

Apply the official fixes provided by Mozilla by upgrading to Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, or Thunderbird 147.0.2. These versions contain the official patches that remediate the heap buffer overflow in libvpx. No additional mitigation is required beyond updating to these fixed versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:5231
Cve Count
1

Threat ID: 6a3da1c14853345fc181dd39

Added to database: 06/25/2026, 21:46:41 UTC

Last enriched: 07/15/2026, 15:56:03 UTC

Last updated: 09/10/2026, 19:36:53 UTC

Views: 67

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses