- What: Security update for Firefox in Red Hat Enterprise Linux 10
- Impact: Systems using Firefox may be vulnerable to issues in the WebRTC component and memory safety bugs
Red Hat Product Errata RHSA-2026:19160 - Security Advisory Issued: 2026-05-19 Updated: 2026-05-19 RHSA-2026:19160 - Security Advisory Overview Updated Packages Synopsis Important: firefox security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for firefox is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. Security Fix(es): firefox: Other issue in the WebRTC component (CVE-2026-8094) firefox: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 (CVE-2026-8092) firefox: Use-after-free in the DOM: Networking component (CVE-2026-8090) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2467706 - CVE-2026-8094 firefox: Other issue in the WebRTC component BZ - 2467708 - CVE-2026-8092 firefox: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 BZ - 2467709 - CVE-2026-8090 firefox: Use-after-free in the DOM: Networking component CVEs CVE-2026-8090 CVE-2026-8092 CVE-2026-8094 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 x86_64 firefox-140.10.2-1.el10_2.x86_64.rpm SHA-256: 7203855960b25d061342984df5d9432f29c4e81381f55e3ac0a0edfd398612c3 firefox-debuginfo-140.10.2-1.el10_2.x86_64.rpm SHA-256: 932d02a7e1aabc38e25e2c8ce1a50e82ed6a50605bbdd303c05a833d194ffe1a firefox-debugsource-140.10.2-1.el10_2.x86_64.rpm SHA-256: 01c30f8d5f085a6d88acee823646725dd92c08ad90a31e33c67bd9feb73bf16c Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 x86_64 firefox-140.10.2-1.el10_2.x86_64.rpm SHA-256: 7203855960b25d061342984df5d9432f29c4e81381f55e3ac0a0edfd398612c3 firefox-debuginfo-140.10.2-1.el10_2.x86_64.rpm SHA-256: 932d02a7e1aabc38e25e2c8ce1a50e82ed6a50605bbdd303c05a833d194ffe1a firefox-debugsource-140.10.2-1.el10_2.x86_64.rpm SHA-256: 01c30f8d5f085a6d88acee823646725dd92c08ad90a31e33c67bd9feb73bf16c Red Hat Enterprise Linux for IBM z Systems 10 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 s390x firefox-140.10.2-1.el10_2.s390x.rpm SHA-256: 28c6c7a8659f84a33ba319beb9d724a64ae05cee84db0bbc34f5ea691d469528 firefox-debuginfo-140.10.2-1.el10_2.s390x.rpm SHA-256: a8bb93130b103a23ce12199b74b0dbb19b6c987bc7b1190f9db541c9414326db firefox-debugsource-140.10.2-1.el10_2.s390x.rpm SHA-256: 4f37dfb29e80498c8edfc1d58385e987dd14703b54d60ad0cd1fcf19740391fd Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 s390x firefox-140.10.2-1.el10_2.s390x.rpm SHA-256: 28c6c7a8659f84a33ba319beb9d724a64ae05cee84db0bbc34f5ea691d469528 firefox-debuginfo-140.10.2-1.el10_2.s390x.rpm SHA-256: a8bb93130b103a23ce12199b74b0dbb19b6c987bc7b1190f9db541c9414326db firefox-debugsource-140.10.2-1.el10_2.s390x.rpm SHA-256: 4f37dfb29e80498c8edfc1d58385e987dd14703b54d60ad0cd1fcf19740391fd Red Hat Enterprise Linux for Power, little endian 10 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 ppc64le firefox-140.10.2-1.el10_2.ppc64le.rpm SHA-256: e6c0d5c2663239a24b823edca31a8cb9c4d40088fecfd093ce4aec6bab3b57d7 firefox-debuginfo-140.10.2-1.el10_2.ppc64le.rpm SHA-256: 97d6bf90cbc4028b20708d1c7fe22090e74ec3be390613f797b8415602150814 firefox-debugsource-140.10.2-1.el10_2.ppc64le.rpm SHA-256: bf88dff1c7e4e96f0e6ee0b14c5a49e16149072db534a6b1a3d8ede54075987c Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 ppc64le firefox-140.10.2-1.el10_2.ppc64le.rpm SHA-256: e6c0d5c2663239a24b823edca31a8cb9c4d40088fecfd093ce4aec6bab3b57d7 firefox-debuginfo-140.10.2-1.el10_2.ppc64le.rpm SHA-256: 97d6bf90cbc4028b20708d1c7fe22090e74ec3be390613f797b8415602150814 firefox-debugsource-140.10.2-1.el10_2.ppc64le.rpm SHA-256: bf88dff1c7e4e96f0e6ee0b14c5a49e16149072db534a6b1a3d8ede54075987c Red Hat Enterprise Linux for ARM 64 10 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 aarch64 firefox-140.10.2-1.el10_2.aarch64.rpm SHA-256: 639af49629476a442beef186f77ed9e821b5c92ec7607f3f1f721c493e33b7aa firefox-debuginfo-140.10.2-1.el10_2.aarch64.rpm SHA-256: 52f5873fe02adf78112a5f96af78ad270a45c1907ae11f42bd69a9244a5135fd firefox-debugsource-140.10.2-1.el10_2.aarch64.rpm SHA-256: 06ddc154b8d6dc4746f657052ad7c13371e3ea5256aa299042b6c290e705f6ce Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 aarch64 firefox-140.10.2-1.el10_2.aarch64.rpm SHA-256: 639af49629476a442beef186f77ed9e821b5c92ec7607f3f1f721c493e33b7aa firefox-debuginfo-140.10.2-1.el10_2.aarch64.rpm SHA-256: 52f5873fe02adf78112a5f96af78ad270a45c1907ae11f42bd69a9244a5135fd firefox-debugsource-140.10.2-1.el10_2.aarch64.rpm SHA-256: 06ddc154b8d6dc4746f657052ad7c13371e3ea5256aa299042b6c290e705f6ce Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 aarch64 firefox-140.10.2-1.el10_2.aarch64.rpm SHA-256: 639af49629476a442beef186f77ed9e821b5c92ec7607f3f1f721c493e33b7aa firefox-debuginfo-140.10.2-1.el10_2.aarch64.rpm SHA-256: 52f5873fe02adf78112a5f96af78ad270a45c1907ae11f42bd69a9244a5135fd firefox-debugsource-140.10.2-1.el10_2.aarch64.rpm SHA-256: 06ddc154b8d6dc4746f657052ad7c13371e3ea5256aa299042b6c290e705f6ce Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 s390x firefox-140.10.2-1.el10_2.s390x.rpm SHA-256: 28c6c7a8659f84a33ba319beb9d724a64ae05cee84db0bbc34f5ea691d469528 firefox-debuginfo-140.10.2-1.el10_2.s390x.rpm SHA-256: a8bb93130b103a23ce12199b74b0dbb19b6c987bc7b1190f9db541c9414326db firefox-debugsource-140.10.2-1.el10_2.s390x.rpm SHA-256: 4f37dfb29e80498c8edfc1d58385e987dd14703b54d60ad0cd1fcf19740391fd Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 ppc64le firefox-140.10.2-1.el10_2.ppc64le.rpm SHA-256: e6c0d5c2663239a24b823edca31a8cb9c4d40088fecfd093ce4aec6bab3b57d7 firefox-debuginfo-140.10.2-1.el10_2.ppc64le.rpm SHA-256: 97d6bf90cbc4028b20708d1c7fe22090e74ec3be390613f797b8415602150814 firefox-debugsource-140.10.2-1.el10_2.ppc64le.rpm SHA-256: bf88dff1c7e4e96f0e6ee0b14c5a49e16149072db534a6b1a3d8ede54075987c Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 x86_64 firefox-140.10.2-1.el10_2.x86_64.rpm SHA-256: 7203855960b25d061342984df5d9432f29c4e81381f55e3ac0a0edfd398612c3 firefox-debuginfo-140.10.2-1.el10_2.x86_64.rpm SHA-256: 932d02a7e1aabc38e25e2c8ce1a50e82ed6a50605bbdd303c05a833d194ffe1a firefox-debugsource-140.10.2-1.el10_2.x86_64.rpm SHA-256: 01c30f8d5f085a6d88acee823646725dd92c08ad90a31e33c67bd9feb73bf16c Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 SRPM firefox-140.10.2-1.el10_2.src.rpm SHA-256: cfee554d15ba431ca78367a628bbdda699edbee22ff58dc8427678eaad7e0a56 x86_64 firefox-140.10.2-1.el10_2.x86_64.rpm SHA-256: 7203855960b25d061342984df5d9432f29c4e81381f55e3ac0a0edfd398612c3 firefox-debuginfo-140.10.2-1.el10_2.x86_64.rpm SHA-256: 932d02a7e1aabc38e25e2c8ce1a50e82ed6a50605bbdd303c05a833d194ffe1a firefox-debugsource-140.10