CVE-2026-2786
Description
Important: thunderbird security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-3516.html
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2026-3339.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-3515.html
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:3515
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2026-3338.html
Vendor advisory: alma — https://bugzilla.redhat.com/2442343
Vendor advisory: alma — https://bugzilla.redhat.com/2442342
Vendor advisory: alma — https://bugzilla.redhat.com/2442337
Vendor advisory: alma — https://bugzilla.redhat.com/2442335
Vendor advisory: alma — https://bugzilla.redhat.com/2442334
Vendor advisory: alma — https://bugzilla.redhat.com/2442333
Vendor advisory: alma — https://bugzilla.redhat.com/2442331
Vendor advisory: alma — https://bugzilla.redhat.com/2442329
Vendor advisory: alma — https://bugzilla.redhat.com/2442328
Vendor advisory: alma — https://bugzilla.redhat.com/2442327
Vendor advisory: alma — https://bugzilla.redhat.com/2442326
Vendor advisory: alma — https://bugzilla.redhat.com/2442325
Vendor advisory: alma — https://bugzilla.redhat.com/2442324
Vendor advisory: alma — https://bugzilla.redhat.com/2442322
Vendor advisory: alma — https://bugzilla.redhat.com/2442320
Vendor advisory: alma — https://bugzilla.redhat.com/2442319
Vendor advisory: alma — https://bugzilla.redhat.com/2442318
Vendor advisory: alma — https://bugzilla.redhat.com/2442316
Vendor advisory: alma — https://bugzilla.redhat.com/2442314
Vendor advisory: alma — https://bugzilla.redhat.com/2442313
Vendor advisory: alma — https://bugzilla.redhat.com/2442312
Vendor advisory: alma — https://bugzilla.redhat.com/2442309
Vendor advisory: alma — https://bugzilla.redhat.com/2442308
Vendor advisory: alma — https://bugzilla.redhat.com/2442307
Vendor advisory: alma — https://bugzilla.redhat.com/2442304
Vendor advisory: alma — https://bugzilla.redhat.com/2442302
Vendor advisory: alma — https://bugzilla.redhat.com/2442300
Vendor advisory: alma — https://bugzilla.redhat.com/2442298
Vendor advisory: alma — https://bugzilla.redhat.com/2442297
Vendor advisory: alma — https://bugzilla.redhat.com/2442295
Vendor advisory: alma — https://bugzilla.redhat.com/2442294
Vendor advisory: alma — https://bugzilla.redhat.com/2442292
Vendor advisory: alma — https://bugzilla.redhat.com/2442291
Vendor advisory: alma — https://bugzilla.redhat.com/2442290
Vendor advisory: alma — https://bugzilla.redhat.com/2442288
Vendor advisory: alma — https://bugzilla.redhat.com/2442287
Vendor advisory: alma — https://bugzilla.redhat.com/2442284
Vendor advisory: alma — https://bugzilla.redhat.com/2440219
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2026:3338
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2026:3339
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-2786.html
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2026:3516
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-2786
Vendor advisory: security@mozilla.org — https://www.mozilla.org/security/advisories/mfsa2026-17/
Vendor advisory: security@mozilla.org — https://www.mozilla.org/security/advisories/mfsa2026-16/
Vendor advisory: security@mozilla.org — https://www.mozilla.org/security/advisories/mfsa2026-15/
Vendor advisory: security@mozilla.org — https://www.mozilla.org/security/advisories/mfsa2026-13/
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:3516
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2026:3339
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2026:3338
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2026:3515
Mitigation details
Description firefox: thunderbird: Use-after-free in the JavaScript Engine component Red Hat statement Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. CVSS v3: 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux…
Description
firefox: thunderbird: Use-after-free in the JavaScript Engine component
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
CVSS v3: 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox-0:140.8.0-2.el10_1 | RHSA-2026:3361 | 2026-02-25T00:00:00Z |
| Red Hat Enterprise Linux 10 | thunderbird-0:140.8.0-2.el10_1 | RHSA-2026:3517 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 10.0 Extended Update Support | firefox-0:140.8.0-2.el10_0 | RHSA-2026:3976 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 10.0 Extended Update Support | thunderbird-0:140.8.0-2.el10_0 | RHSA-2026:4260 | 2026-03-11T00:00:00Z |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | firefox-0:140.8.0-2.el7_9 | RHSA-2026:3984 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 8 | firefox-0:140.8.0-2.el8_10 | RHSA-2026:3338 | 2026-02-25T00:00:00Z |
| Red Hat Enterprise Linux 8 | thunderbird-0:140.8.0-1.el8_10 | RHSA-2026:3515 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | firefox-0:140.8.0-2.el8_2 | RHSA-2026:3492 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | thunderbird-0:140.8.0-1.el8_2 | RHSA-2026:4432 | 2026-03-12T00:00:00Z |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | firefox-0:140.8.0-2.el8_4 | RHSA-2026:3491 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:140.8.0-2.el8_4 | RHSA-2026:3980 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | firefox-0:140.8.0-2.el8_4 | RHSA-2026:3491 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | thunderbird-0:140.8.0-2.el8_4 | RHSA-2026:3980 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | firefox-0:140.8.0-2.el8_6 | RHSA-2026:3495 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | thunderbird-0:140.8.0-1.el8_6 | RHSA-2026:3979 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | firefox-0:140.8.0-2.el8_6 | RHSA-2026:3495 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | thunderbird-0:140.8.0-1.el8_6 | RHSA-2026:3979 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | firefox-0:140.8.0-2.el8_6 | RHSA-2026:3495 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | thunderbird-0:140.8.0-1.el8_6 | RHSA-2026:3979 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | firefox-0:140.8.0-2.el8_8 | RHSA-2026:3494 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | thunderbird-0:140.8.0-1.el8_8 | RHSA-2026:4022 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | firefox-0:140.8.0-2.el8_8 | RHSA-2026:3494 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | thunderbird-0:140.8.0-1.el8_8 | RHSA-2026:4022 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 9 | firefox-0:140.8.0-2.el9_7 | RHSA-2026:3339 | 2026-02-25T00:00:00Z |
| Red Hat Enterprise Linux 9 | thunderbird-0:140.8.0-1.el9_7 | RHSA-2026:3516 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | firefox-0:140.8.0-2.el9_0 | RHSA-2026:3493 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | thunderbird-0:140.8.0-1.el9_0 | RHSA-2026:3983 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | thunderbird-0:140.8.0-1.el9_2 | RHSA-2026:3978 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | firefox-0:140.8.0-2.el9_2 | RHSA-2026:4152 | 2026-03-10T00:00:00Z |
| Red Hat Enterprise Linux 9.4 Extended Update Support | firefox-0:140.8.0-2.el9_4 | RHSA-2026:3496 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 9.4 Extended Update Support | thunderbird-0:140.8.0-1.el9_4 | RHSA-2026:3981 | 2026-03-09T00:00:00Z |
| Red Hat Enterprise Linux 9.6 Extended Update Support | firefox-0:140.8.0-2.el9_6 | RHSA-2026:3497 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 9.6 Extended Update Support | thunderbird-0:140.8.0-1.el9_6 | RHSA-2026:3982 | 2026-03-09T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 10 | rhel10/firefox-flatpak | Affected |
| Red Hat Enterprise Linux 10 | rhel10/thunderbird-flatpak | Affected |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope |
| Red Hat Enterprise Linux 7 | thunderbird | Out of support scope |
Apply commands
yum update -y firefox
# or:
dnf upgrade -y firefox
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 10 | Affected |
| redhat | Red Hat Enterprise Linux 10 | Affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rocky | 8 | fixed | |
| rhel | 9 | fixed | |
| debian | sid | fixed | 148.0-1 |
| debian | bookworm | fixed | 140.8.0esr-1~deb12u1 |
| debian | bullseye | fixed | 140.8.0esr-1~deb11u1 |
| debian | forky | fixed | 140.8.0esr-1 |
| debian | trixie | fixed | 140.8.0esr-1~deb13u1 |
| rocky | 9 | fixed | |
| sles | affected | | |
| almalinux | 8 | fixed | firefox-140.8.0-2.el8_10.alma.1.x86_64.rpm |
| almalinux | 9 | fixed | firefox-x11-140.8.0-2.el9_7.alma.1.x86_64.rpm |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| mozilla | firefox | {"endExcluding":"140.8.0"} | 140.8.0 |
| mozilla | thunderbird | {"endExcluding":"140.8.0"} | 140.8.0 |
References
- https://errata.rockylinux.org/RLSA-2026:3515
- https://errata.rockylinux.org/RLSA-2026:3338
- https://access.redhat.com/errata/RHSA-2026:3339
- https://access.redhat.com/errata/RHSA-2026:3516
- https://bugzilla.mozilla.org/show_bug.cgi?id=2013612
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://security-tracker.debian.org/tracker/CVE-2026-2786
- https://errata.rockylinux.org/RLSA-2026:3516
- https://www.suse.com/security/cve/CVE-2026-2786.html
- https://errata.rockylinux.org/RLSA-2026:3339
- https://access.redhat.com/errata/RHSA-2026:3338
- https://bugzilla.redhat.com/2440219
- https://bugzilla.redhat.com/2442284
- https://bugzilla.redhat.com/2442287
- https://bugzilla.redhat.com/2442288
- https://bugzilla.redhat.com/2442290
- https://bugzilla.redhat.com/2442291
- https://bugzilla.redhat.com/2442292
- https://bugzilla.redhat.com/2442294
- https://bugzilla.redhat.com/2442295
- https://bugzilla.redhat.com/2442297
- https://bugzilla.redhat.com/2442298
CWEs
CWE-416
Verify integrity in audit chain (admin only). AS-IS.