Red Hat Security Advisory: firefox security update
Multiple security vulnerabilities affecting Mozilla Firefox and Thunderbird have been addressed in Red Hat Enterprise Linux 8.4 updates. These include memory safety bugs, use-after-free, JIT miscompilation, sandbox escape, privilege escalation, and same-origin policy bypass issues across various components such as WebRTC, JavaScript engine, graphics, netmonitor, request handling, and DOM notifications. The update is rated as important by Red Hat Product Security and fixes these issues in Firefox ESR 140.6 and Firefox 146 versions.
AI Analysis
Technical Summary
Red Hat Product Security issued an advisory (RHSA-2026:0006) for Firefox security updates addressing ten CVEs (CVE-2025-14321 through CVE-2025-14333) affecting Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146, and Thunderbird 146. The vulnerabilities include use-after-free in WebRTC signaling, multiple JIT miscompilation flaws in the JavaScript engine, sandbox escape via incorrect boundary conditions in the CanvasWebGL graphics component, privilege escalation in Netmonitor and DOM Notifications components, same-origin policy bypass in request handling, and memory safety bugs. These issues collectively represent significant security risks and have been fixed in the updated packages provided by Red Hat for RHEL 8.4 Extended Update Support and Advanced Update Support.
Potential Impact
The vulnerabilities fixed include memory safety bugs, use-after-free conditions, sandbox escape, privilege escalation, and same-origin policy bypass, which could allow attackers to execute arbitrary code, escalate privileges, bypass security policies, or escape sandbox restrictions. These issues affect core browser components and could compromise the confidentiality, integrity, and security of affected systems if exploited. No known exploits in the wild have been reported at the time of this advisory.
Mitigation Recommendations
Red Hat has released updated Firefox packages for Red Hat Enterprise Linux 8.4 Extended Update Support and Advanced Update Support that address these vulnerabilities. Users should apply these official updates promptly to remediate the issues. For detailed update instructions, refer to Red Hat's advisory and article at https://access.redhat.com/articles/11258. No additional mitigations are specified beyond applying the provided patches.
Red Hat Security Advisory: firefox security update
Description
Multiple security vulnerabilities affecting Mozilla Firefox and Thunderbird have been addressed in Red Hat Enterprise Linux 8.4 updates. These include memory safety bugs, use-after-free, JIT miscompilation, sandbox escape, privilege escalation, and same-origin policy bypass issues across various components such as WebRTC, JavaScript engine, graphics, netmonitor, request handling, and DOM notifications. The update is rated as important by Red Hat Product Security and fixes these issues in Firefox ESR 140.6 and Firefox 146 versions.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat Product Security issued an advisory (RHSA-2026:0006) for Firefox security updates addressing ten CVEs (CVE-2025-14321 through CVE-2025-14333) affecting Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146, and Thunderbird 146. The vulnerabilities include use-after-free in WebRTC signaling, multiple JIT miscompilation flaws in the JavaScript engine, sandbox escape via incorrect boundary conditions in the CanvasWebGL graphics component, privilege escalation in Netmonitor and DOM Notifications components, same-origin policy bypass in request handling, and memory safety bugs. These issues collectively represent significant security risks and have been fixed in the updated packages provided by Red Hat for RHEL 8.4 Extended Update Support and Advanced Update Support.
Potential Impact
The vulnerabilities fixed include memory safety bugs, use-after-free conditions, sandbox escape, privilege escalation, and same-origin policy bypass, which could allow attackers to execute arbitrary code, escalate privileges, bypass security policies, or escape sandbox restrictions. These issues affect core browser components and could compromise the confidentiality, integrity, and security of affected systems if exploited. No known exploits in the wild have been reported at the time of this advisory.
Mitigation Recommendations
Red Hat has released updated Firefox packages for Red Hat Enterprise Linux 8.4 Extended Update Support and Advanced Update Support that address these vulnerabilities. Users should apply these official updates promptly to remediate the issues. For detailed update instructions, refer to Red Hat's advisory and article at https://access.redhat.com/articles/11258. No additional mitigations are specified beyond applying the provided patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:0006
- Cve Count
- 10
- Additional Cves
- ["CVE-2025-14322","CVE-2025-14323","CVE-2025-14324","CVE-2025-14325","CVE-2025-14328","CVE-2025-14329","CVE-2025-14330","CVE-2025-14331","CVE-2025-14333"]
Threat ID: 6a4049df27e9c79719831b2c
Added to database: 06/27/2026, 22:08:31 UTC
Last enriched: 06/27/2026, 22:27:00 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.