SB20261007246 - Red Hat Enterprise Linux 10 update for firefox
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 43 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2026-100785)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
2) Use-after-free (CVE-ID: CVE-2026-100811)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing content. A remote attacker can cause the component to access freed memory to escape the browser sandbox.
3) Use-after-free (CVE-ID: CVE-2026-100772)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.
4) Use of uninitialized resource (CVE-ID: CVE-2026-100759)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to uninitialized memory in the Storage: Quota Manager component when it is used. A remote attacker can trigger use of uninitialized memory to execute arbitrary code.
5) Use-after-free (CVE-ID: CVE-2026-100778)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.
6) Protection mechanism failure (CVE-ID: CVE-2026-100758)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper sandbox enforcement in the DOM: Navigation component when it is used. A remote attacker can trigger the sandbox escape to escape the sandbox.
7) Protection mechanism failure (CVE-ID: CVE-2026-100775)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper sandbox enforcement in the Graphics component when it is used. A remote attacker can trigger the sandbox escape to escape the sandbox.
8) Off-by-one (CVE-ID: CVE-2026-100781)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the Graphics: WebRender component when it is used. A remote attacker can trigger the boundary-condition flaw to escape the sandbox.
9) Use-after-free (CVE-ID: CVE-2026-100774)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
10) Origin validation error (CVE-ID: CVE-2026-100803)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper origin validation in the WebExtensions component when it is used. A remote attacker can trigger the policy bypass to bypass the same-origin policy.
11) Use-after-free (CVE-ID: CVE-2026-100789)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
12) Off-by-one (CVE-ID: CVE-2026-100782)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when it is used. A remote attacker can trigger the boundary-condition flaw to escalate privileges.
13) Protection mechanism failure (CVE-ID: CVE-2026-100821)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper site isolation in the Panning and Zooming component when it is used. A remote attacker can trigger the site-isolation issue to bypass site isolation.
14) Untrusted Pointer Dereference (CVE-ID: CVE-2026-100788)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger invalid pointer handling.
The vulnerability exists due to an invalid pointer in the JavaScript: WebAssembly component when processing content. A remote attacker can trigger invalid pointer handling to trigger invalid pointer handling.
15) Reliance on undefined behavior (CVE-ID: CVE-2026-100771)
CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to undefined behavior in the DOM: Streams component when it is used. A remote attacker can trigger the undefined behavior to execute arbitrary code.
16) Use-after-free (CVE-ID: CVE-2026-100762)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Content Processes component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.
17) Use-after-free (CVE-ID: CVE-2026-100790)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the XSLT component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
18) Use-after-free (CVE-ID: CVE-2026-100773)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Storage: IndexedDB component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
19) Use-after-free (CVE-ID: CVE-2026-100780)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
20) Use-after-free (CVE-ID: CVE-2026-100767)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Networking: Cache component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
21) Off-by-one (CVE-ID: CVE-2026-100756)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Playback component when it is used. A remote attacker can trigger the boundary-condition flaw to execute arbitrary code.
22) Use of uninitialized resource (CVE-ID: CVE-2026-100783)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to uninitialized memory in the Audio/Video component when it is used. A remote attacker can trigger use of uninitialized memory to execute arbitrary code.
23) Use-after-free (CVE-ID: CVE-2026-100797)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use-after-free in the Graphics: WebRender component when it is used. A remote attacker can trigger the use-after-free to escalate privileges.
24) Use-after-free (CVE-ID: CVE-2026-100832)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
25) Use-after-free (CVE-ID: CVE-2026-100784)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Layout: Text and Fonts component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
26) Improper privilege management (CVE-ID: CVE-2026-100801)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the DLL Services component when processing content. A remote attacker can trigger the component issue to escalate privileges.
27) Off-by-one (CVE-ID: CVE-2026-100794)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to incorrect boundary conditions in the Internationalization component when processing content. A remote attacker can trigger the incorrect boundary condition to escape the browser sandbox.
28) Improper privilege management (CVE-ID: CVE-2026-100820)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the Address Bar component when processing content. A remote attacker can trigger the component issue to escalate privileges.
29) Use-after-free (CVE-ID: CVE-2026-100777)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
30) Information disclosure (CVE-ID: CVE-2026-100766)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper information handling in the Networking: JAR component when it is used. A remote attacker can trigger the information disclosure to disclose sensitive information.
31) Use-after-free (CVE-ID: CVE-2026-100779)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the XSLT component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
32) Improper privilege management (CVE-ID: CVE-2026-100807)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the DOM: Service Workers component when processing content. A remote attacker can trigger the component issue to escalate privileges.
33) Incorrect calculation (CVE-ID: CVE-2026-100792)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a JIT miscompilation.
The vulnerability exists due to JIT miscompilation in the JavaScript: WebAssembly component when processing content. A remote attacker can trigger JIT compilation to trigger a JIT miscompilation.
34) Input validation error (CVE-ID: CVE-2026-92035)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing input. A remote attacker can process input to escape the sandbox.
35) Off-by-one (CVE-ID: CVE-2026-100819)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the XPCOM component when it is used. A remote attacker can trigger the boundary-condition flaw to escape the sandbox.
36) Use-after-free (CVE-ID: CVE-2026-100776)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.
37) Use-after-free (CVE-ID: CVE-2026-100757)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Widget component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
38) Use-after-free (CVE-ID: CVE-2026-100786)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Graphics component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.
39) Information disclosure (CVE-ID: CVE-2026-96869)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an information disclosure issue in the Networking component when processing content. A remote attacker can trigger the issue to disclose information.
40) Use-after-free (CVE-ID: CVE-2026-100770)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Content Processes component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.
41) Use-after-free (CVE-ID: CVE-2026-100769)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.
42) Use-after-free (CVE-ID: CVE-2026-100791)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
43) Use-after-free (CVE-ID: CVE-2026-100818)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to use-after-free in the Widget: Gtk component when processing content. A remote attacker can cause the component to access freed memory to escape the browser sandbox.
Remediation
Install update from vendor's website.