Buffer overflow in Mozilla Firefox and Firefox for Android - CVE-2026-74989
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to memory corruption in multiple unspecified components when processing web content. A remote attacker can supply crafted web content to cause a denial of service.
Some of the internally found bugs showed evidence of memory corruption or another security-relevant defect.
Affected software
Firefox for Android
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Desktop Applications Module
Mozilla Thunderbird
MozillaFirefox-translations-common
MozillaFirefox-debugsource
MozillaFirefox-debuginfo
MozillaFirefox
MozillaFirefox-devel
MozillaFirefox-translations-other
How to mitigate CVE-2026-74989
Firefox for Android - update to 154.0
Mozilla Thunderbird - update to 154.0
MozillaFirefox-translations-common - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox-debugsource - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox-debuginfo - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox-devel - addressed in versions 140.14.0-112.327.1, 140.14.0-150200.152.251.1
MozillaFirefox-translations-other - update to 140.14.0-150200.152.251.1