Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
Published Apr 21, 2026
7.5
HIGHCVSS 3.1
EPSS 0.53%
Description
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Affected products
No data.
No data.
Red Hat Enterprise Linux 10
firefox-0:140.10.0-1.el10_1
Fixed · RHSA-2026:10767
Red Hat Enterprise Linux 10
firefox-0:140.10.0-1.el10_2
Fixed · RHSA-2026:19041
Red Hat Enterprise Linux 10
thunderbird-0:140.10.0-1.el10_1
Fixed · RHSA-2026:12285
Red Hat Enterprise Linux 10
thunderbird-0:140.10.0-1.el10_2
Fixed · RHSA-2026:19131
Red Hat Enterprise Linux 10.0 Extended Update Support
firefox-0:140.10.0-1.el10_0
Fixed · RHSA-2026:17690
Red Hat Enterprise Linux 10.0 Extended Update Support
thunderbird-0:140.10.0-1.el10_0
Fixed · RHSA-2026:19463
Red Hat Enterprise Linux 7 Extended Lifecycle Support
firefox-0:140.10.0-2.el7_9
Fixed · RHSA-2026:19704
Red Hat Enterprise Linux 8
firefox-0:140.10.0-1.el8_10
Fixed · RHSA-2026:10766
Red Hat Enterprise Linux 8
thunderbird-0:140.10.0-1.el8_10
Fixed · RHSA-2026:13537
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
firefox-0:140.10.0-1.el8_4
Fixed · RHSA-2026:19655
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
thunderbird-0:140.10.0-1.el8_4
Fixed · RHSA-2026:19465
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
firefox-0:140.10.0-1.el8_4
Fixed · RHSA-2026:19655
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
thunderbird-0:140.10.0-1.el8_4
Fixed · RHSA-2026:19465
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
firefox-0:140.10.0-1.el8_6
Fixed · RHSA-2026:19542
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
thunderbird-0:140.10.0-1.el8_6
Fixed · RHSA-2026:19466
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
firefox-0:140.10.0-1.el8_6
Fixed · RHSA-2026:19542
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
thunderbird-0:140.10.0-1.el8_6
Fixed · RHSA-2026:19466
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
firefox-0:140.10.0-1.el8_6
Fixed · RHSA-2026:19542
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
thunderbird-0:140.10.0-1.el8_6
Fixed · RHSA-2026:19466
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
firefox-0:140.10.0-1.el8_8
Fixed · RHSA-2026:17477
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
thunderbird-0:140.10.0-1.el8_8
Fixed · RHSA-2026:19467
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
firefox-0:140.10.0-1.el8_8
Fixed · RHSA-2026:17477
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
thunderbird-0:140.10.0-1.el8_8
Fixed · RHSA-2026:19467
Red Hat Enterprise Linux 9
firefox-0:140.10.0-1.el9_7
Fixed · RHSA-2026:10757
Red Hat Enterprise Linux 9
firefox-0:140.10.0-1.el9_8
Fixed · RHSA-2026:19201
Red Hat Enterprise Linux 9
thunderbird-0:140.10.0-1.el9_7
Fixed · RHSA-2026:15892
Red Hat Enterprise Linux 9
thunderbird-0:140.10.1-1.el9_8
Fixed · RHSA-2026:19348
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
firefox-0:140.10.0-1.el9_0
Fixed · RHSA-2026:17687
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
thunderbird-0:140.10.0-1.el9_0
Fixed · RHSA-2026:19468
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
firefox-0:140.10.0-1.el9_2
Fixed · RHSA-2026:17689
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
thunderbird-0:140.10.0-1.el9_2
Fixed · RHSA-2026:19461
Red Hat Enterprise Linux 9.4 Extended Update Support
firefox-0:140.10.0-1.el9_4
Fixed · RHSA-2026:19464
Red Hat Enterprise Linux 9.4 Extended Update Support
thunderbird-0:140.10.0-1.el9_4
Fixed · RHSA-2026:19469
Red Hat Enterprise Linux 9.6 Extended Update Support
firefox-0:140.10.0-1.el9_6
Fixed · RHSA-2026:17688
Red Hat Enterprise Linux 9.6 Extended Update Support
thunderbird-0:140.10.0-1.el9_6
Fixed · RHSA-2026:19462
Red Hat Enterprise Linux 10
rhel10/firefox-flatpak
Affected
Red Hat Enterprise Linux 10
rhel10/thunderbird-flatpak
Affected
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
Red Hat Enterprise Linux 7
thunderbird
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox-0:140.10.0-1.el10_1 | Fixed | RHSA-2026:10767 |
| Red Hat Enterprise Linux 10 | firefox-0:140.10.0-1.el10_2 | Fixed | RHSA-2026:19041 |
| Red Hat Enterprise Linux 10 | thunderbird-0:140.10.0-1.el10_1 | Fixed | RHSA-2026:12285 |
| Red Hat Enterprise Linux 10 | thunderbird-0:140.10.0-1.el10_2 | Fixed | RHSA-2026:19131 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | firefox-0:140.10.0-1.el10_0 | Fixed | RHSA-2026:17690 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | thunderbird-0:140.10.0-1.el10_0 | Fixed | RHSA-2026:19463 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | firefox-0:140.10.0-2.el7_9 | Fixed | RHSA-2026:19704 |
| Red Hat Enterprise Linux 8 | firefox-0:140.10.0-1.el8_10 | Fixed | RHSA-2026:10766 |
| Red Hat Enterprise Linux 8 | thunderbird-0:140.10.0-1.el8_10 | Fixed | RHSA-2026:13537 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | firefox-0:140.10.0-1.el8_4 | Fixed | RHSA-2026:19655 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:140.10.0-1.el8_4 | Fixed | RHSA-2026:19465 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | firefox-0:140.10.0-1.el8_4 | Fixed | RHSA-2026:19655 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | thunderbird-0:140.10.0-1.el8_4 | Fixed | RHSA-2026:19465 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | firefox-0:140.10.0-1.el8_6 | Fixed | RHSA-2026:19542 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | thunderbird-0:140.10.0-1.el8_6 | Fixed | RHSA-2026:19466 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | firefox-0:140.10.0-1.el8_6 | Fixed | RHSA-2026:19542 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | thunderbird-0:140.10.0-1.el8_6 | Fixed | RHSA-2026:19466 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | firefox-0:140.10.0-1.el8_6 | Fixed | RHSA-2026:19542 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | thunderbird-0:140.10.0-1.el8_6 | Fixed | RHSA-2026:19466 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | firefox-0:140.10.0-1.el8_8 | Fixed | RHSA-2026:17477 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | thunderbird-0:140.10.0-1.el8_8 | Fixed | RHSA-2026:19467 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | firefox-0:140.10.0-1.el8_8 | Fixed | RHSA-2026:17477 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | thunderbird-0:140.10.0-1.el8_8 | Fixed | RHSA-2026:19467 |
| Red Hat Enterprise Linux 9 | firefox-0:140.10.0-1.el9_7 | Fixed | RHSA-2026:10757 |
| Red Hat Enterprise Linux 9 | firefox-0:140.10.0-1.el9_8 | Fixed | RHSA-2026:19201 |
| Red Hat Enterprise Linux 9 | thunderbird-0:140.10.0-1.el9_7 | Fixed | RHSA-2026:15892 |
| Red Hat Enterprise Linux 9 | thunderbird-0:140.10.1-1.el9_8 | Fixed | RHSA-2026:19348 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | firefox-0:140.10.0-1.el9_0 | Fixed | RHSA-2026:17687 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | thunderbird-0:140.10.0-1.el9_0 | Fixed | RHSA-2026:19468 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | firefox-0:140.10.0-1.el9_2 | Fixed | RHSA-2026:17689 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | thunderbird-0:140.10.0-1.el9_2 | Fixed | RHSA-2026:19461 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | firefox-0:140.10.0-1.el9_4 | Fixed | RHSA-2026:19464 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | thunderbird-0:140.10.0-1.el9_4 | Fixed | RHSA-2026:19469 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | firefox-0:140.10.0-1.el9_6 | Fixed | RHSA-2026:17688 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | thunderbird-0:140.10.0-1.el9_6 | Fixed | RHSA-2026:19462 |
| Red Hat Enterprise Linux 10 | rhel10/firefox-flatpak | Affected | n/a |
| Red Hat Enterprise Linux 10 | rhel10/thunderbird-flatpak | Affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
References (41)
- https://access.redhat.com/errata/RHSA-2026:10757
- https://access.redhat.com/errata/RHSA-2026:10766
- https://access.redhat.com/errata/RHSA-2026:10767
- https://access.redhat.com/errata/RHSA-2026:12285
- https://access.redhat.com/errata/RHSA-2026:13537
- https://access.redhat.com/errata/RHSA-2026:15892
- https://access.redhat.com/errata/RHSA-2026:17477
- https://access.redhat.com/errata/RHSA-2026:17687
- https://access.redhat.com/errata/RHSA-2026:17688
- https://access.redhat.com/errata/RHSA-2026:17689
- https://access.redhat.com/errata/RHSA-2026:17690
- https://access.redhat.com/errata/RHSA-2026:19041
- https://access.redhat.com/errata/RHSA-2026:19131
- https://access.redhat.com/errata/RHSA-2026:19201
- https://access.redhat.com/errata/RHSA-2026:19348
- https://access.redhat.com/errata/RHSA-2026:19461
- https://access.redhat.com/errata/RHSA-2026:19462
- https://access.redhat.com/errata/RHSA-2026:19463
- https://access.redhat.com/errata/RHSA-2026:19464
- https://access.redhat.com/errata/RHSA-2026:19465
- https://access.redhat.com/errata/RHSA-2026:19466
- https://access.redhat.com/errata/RHSA-2026:19467
- https://access.redhat.com/errata/RHSA-2026:19468
- https://access.redhat.com/errata/RHSA-2026:19469
- https://access.redhat.com/errata/RHSA-2026:19542
- https://access.redhat.com/errata/RHSA-2026:19655
- https://access.redhat.com/errata/RHSA-2026:19704
- https://access.redhat.com/security/cve/CVE-2026-6785 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1935995%2C1999158%2C2015952%2C2021909%2C2022026%2C2022041%2C2022088%2C2022276%2C2022335%2C2022338%2C2022373%2C2022597%2C2022874%2C2023276%2C2023544%2C2023551%2C2023599%2C2023608%2C2023814%2C2024233%2C2024239%2C2024241%2C2024242%2C2024250%2C2024251%2C2024343%2C2024422%2C2024425%2C2024440%2C2024442%2C2024446%2C2024458%2C2024463%2C2024478%2C2024650%2C2024653%2C2024654%2C2024655%2C2024656%2C2024661%2C2024662%2C2024668%2C2024919%2C2025278%2C2025349%2C2025350%2C2025354%2C2025360%2C2025363%2C2025370%2C2025379%2C2025381%2C2025399%2C2025400%2C2025403%2C2025407%2C2025415%2C2025420%2C2025427%2C2025429%2C2025430%2C2025479%2C2025489%2C2025493%2C2025497%2C2025502%2C2025515%2C2025517%2C2025526%2C2025609%2C2025948%2C2025949%2C2025951%2C2025953%2C2025955%2C2025962%2C2025969%2C2025970%2C2025971%2C2025973%2C2025976%2C2025977%2C2026280%2C2026285%2C2026293%2C2026296%2C2026310%2C2027237%2C2027260%2C2027268%2C2027277%2C2027284%2C2027291%2C2027293%2C2027298%2C2027330%2C2027342%2C2027345%2C2027359%2C2027365%2C2027378%2C2027754%2C2027959%2C2027962%2C2027964%2C2027971%2C2027974%2C2027979%2C2027982%2C2027995%2C2028001%2C2028267%2C2028268%2C2028275%2C2028288%2C2028290%2C2028291%2C2028528%2C2028551%2C2028627%2C2028879%2C2028889%2C2029061%2C2029071%2C2029283%2C2029296%2C2029314%2C2029323%2C2029411%2C2029423%2C2029424%2C2029425%2C2029427%2C2029436%2C2029440%2C2029449%2C2029450%2C2029458%2C2029462%2C2029468%2C2029472%2C2029690%2C2029707%2C2029708%2C2029728%2C2029802%2C2029896%2C2029906%2C2030106%2C2030118%2C2030123%2C2030135%2C2030230%2C2030320 Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=2460104 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24126 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6785
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6785.json
- https://www.cve.org/CVERecord?id=CVE-2026-6785
- https://www.mozilla.org/security/advisories/mfsa2026-30/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-31/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-32/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-32/#CVE-2026-6785
- https://www.mozilla.org/security/advisories/mfsa2026-33/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-34/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-34/#CVE-2026-6785
Change history (0)
No recorded changes yet.