SB20261007246 - Red Hat Enterprise Linux 10 update for firefox



SB20261007246 - Red Hat Enterprise Linux 10 update for firefox

Published: October 7, 2026

Security Bulletin ID SB20261007246
CSH Severity
High
Patch available
YES
Number of vulnerabilities 43
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 58% Medium 35% Low 7%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 43 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2026-100785)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


2) Use-after-free (CVE-ID: CVE-2026-100811)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the browser sandbox.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing content. A remote attacker can cause the component to access freed memory to escape the browser sandbox.


3) Use-after-free (CVE-ID: CVE-2026-100772)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.


4) Use of uninitialized resource (CVE-ID: CVE-2026-100759)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to uninitialized memory in the Storage: Quota Manager component when it is used. A remote attacker can trigger use of uninitialized memory to execute arbitrary code.


5) Use-after-free (CVE-ID: CVE-2026-100778)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.


6) Protection mechanism failure (CVE-ID: CVE-2026-100758)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper sandbox enforcement in the DOM: Navigation component when it is used. A remote attacker can trigger the sandbox escape to escape the sandbox.


7) Protection mechanism failure (CVE-ID: CVE-2026-100775)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper sandbox enforcement in the Graphics component when it is used. A remote attacker can trigger the sandbox escape to escape the sandbox.


8) Off-by-one (CVE-ID: CVE-2026-100781)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions in the Graphics: WebRender component when it is used. A remote attacker can trigger the boundary-condition flaw to escape the sandbox.


9) Use-after-free (CVE-ID: CVE-2026-100774)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


10) Origin validation error (CVE-ID: CVE-2026-100803)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass the same-origin policy.

The vulnerability exists due to improper origin validation in the WebExtensions component when it is used. A remote attacker can trigger the policy bypass to bypass the same-origin policy.


11) Use-after-free (CVE-ID: CVE-2026-100789)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


12) Off-by-one (CVE-ID: CVE-2026-100782)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to incorrect boundary conditions in the Graphics component when it is used. A remote attacker can trigger the boundary-condition flaw to escalate privileges.


13) Protection mechanism failure (CVE-ID: CVE-2026-100821)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass site isolation.

The vulnerability exists due to improper site isolation in the Panning and Zooming component when it is used. A remote attacker can trigger the site-isolation issue to bypass site isolation.


14) Untrusted Pointer Dereference (CVE-ID: CVE-2026-100788)

CWE-ID: CWE-822 - Untrusted Pointer Dereference

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger invalid pointer handling.

The vulnerability exists due to an invalid pointer in the JavaScript: WebAssembly component when processing content. A remote attacker can trigger invalid pointer handling to trigger invalid pointer handling.


15) Reliance on undefined behavior (CVE-ID: CVE-2026-100771)

CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to undefined behavior in the DOM: Streams component when it is used. A remote attacker can trigger the undefined behavior to execute arbitrary code.


16) Use-after-free (CVE-ID: CVE-2026-100762)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in the DOM: Content Processes component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.


17) Use-after-free (CVE-ID: CVE-2026-100790)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the XSLT component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


18) Use-after-free (CVE-ID: CVE-2026-100773)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Storage: IndexedDB component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


19) Use-after-free (CVE-ID: CVE-2026-100780)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


20) Use-after-free (CVE-ID: CVE-2026-100767)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Networking: Cache component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


21) Off-by-one (CVE-ID: CVE-2026-100756)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Playback component when it is used. A remote attacker can trigger the boundary-condition flaw to execute arbitrary code.


22) Use of uninitialized resource (CVE-ID: CVE-2026-100783)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to uninitialized memory in the Audio/Video component when it is used. A remote attacker can trigger use of uninitialized memory to execute arbitrary code.


23) Use-after-free (CVE-ID: CVE-2026-100797)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to use-after-free in the Graphics: WebRender component when it is used. A remote attacker can trigger the use-after-free to escalate privileges.


24) Use-after-free (CVE-ID: CVE-2026-100832)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


25) Use-after-free (CVE-ID: CVE-2026-100784)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Layout: Text and Fonts component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


26) Improper privilege management (CVE-ID: CVE-2026-100801)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper privilege management in the DLL Services component when processing content. A remote attacker can trigger the component issue to escalate privileges.


27) Off-by-one (CVE-ID: CVE-2026-100794)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the browser sandbox.

The vulnerability exists due to incorrect boundary conditions in the Internationalization component when processing content. A remote attacker can trigger the incorrect boundary condition to escape the browser sandbox.


28) Improper privilege management (CVE-ID: CVE-2026-100820)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper privilege management in the Address Bar component when processing content. A remote attacker can trigger the component issue to escalate privileges.


29) Use-after-free (CVE-ID: CVE-2026-100777)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


30) Information disclosure (CVE-ID: CVE-2026-100766)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper information handling in the Networking: JAR component when it is used. A remote attacker can trigger the information disclosure to disclose sensitive information.


31) Use-after-free (CVE-ID: CVE-2026-100779)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the XSLT component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


32) Improper privilege management (CVE-ID: CVE-2026-100807)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper privilege management in the DOM: Service Workers component when processing content. A remote attacker can trigger the component issue to escalate privileges.


33) Incorrect calculation (CVE-ID: CVE-2026-100792)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a JIT miscompilation.

The vulnerability exists due to JIT miscompilation in the JavaScript: WebAssembly component when processing content. A remote attacker can trigger JIT compilation to trigger a JIT miscompilation.


34) Input validation error (CVE-ID: CVE-2026-92035)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing input. A remote attacker can process input to escape the sandbox.


35) Off-by-one (CVE-ID: CVE-2026-100819)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions in the XPCOM component when it is used. A remote attacker can trigger the boundary-condition flaw to escape the sandbox.


36) Use-after-free (CVE-ID: CVE-2026-100776)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.


37) Use-after-free (CVE-ID: CVE-2026-100757)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Widget component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


38) Use-after-free (CVE-ID: CVE-2026-100786)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in the Graphics component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.


39) Information disclosure (CVE-ID: CVE-2026-96869)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose information.

The vulnerability exists due to an information disclosure issue in the Networking component when processing content. A remote attacker can trigger the issue to disclose information.


40) Use-after-free (CVE-ID: CVE-2026-100770)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in the DOM: Content Processes component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.


41) Use-after-free (CVE-ID: CVE-2026-100769)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger a use-after-free condition.

The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.


42) Use-after-free (CVE-ID: CVE-2026-100791)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.


43) Use-after-free (CVE-ID: CVE-2026-100818)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the browser sandbox.

The vulnerability exists due to use-after-free in the Widget: Gtk component when processing content. A remote attacker can cause the component to access freed memory to escape the browser sandbox.


Remediation

Install update from vendor's website.