Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Release firefox-140.10.0-1.el9_8 ALSA-2026:19201

Open
#2,619 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Quiet
Domain
release, security

Research direction

The issue names no repository files, tests, or entry points. Start with the affected firefox and firefox-x11 package entries and the listed CVE references; completion would require confirming that the 140.10.0-1.el9_8 update is represented for every listed architecture.

Written by the indexing model from the issue text.

Description

firefox security update
Severity: Important
Description
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

  • firefox: thunderbird: Incorrect boundary conditions in the Libraries component in NSS (CVE-2026-6772)
  • firefox: thunderbird: Use-after-free in the JavaScript Engine component (CVE-2026-6754)
  • firefox: thunderbird: Spoofing issue in the DOM: Core & HTML component (CVE-2026-6762)
  • firefox: thunderbird: Incorrect boundary conditions in the WebRTC component (CVE-2026-6752)
  • firefox: thunderbird: Other issue in the Storage: IndexedDB component (CVE-2026-6770)
  • firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-6757)
  • firefox: thunderbird: Other issue in the Libraries component in NSS (CVE-2026-6767)
  • firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (CVE-2026-6786)
  • firefox: thunderbird: Incorrect boundary conditions in the WebRTC component (CVE-2026-6753)
  • firefox: thunderbird: Use-after-free in the Widget: Cocoa component (CVE-2026-6759)
  • firefox: thunderbird: Use-after-free in the WebRTC component (CVE-2026-6747)
  • firefox: thunderbird: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component (CVE-2026-6749)
  • firefox: thunderbird: Incorrect boundary conditions in the Libraries component in NSS (CVE-2026-6766)
  • firefox: thunderbird: Privilege escalation in the Networking component (CVE-2026-6761)
  • firefox: thunderbird: Mitigation bypass in the File Handling component (CVE-2026-6763)
  • firefox: thunderbird: Privilege escalation in the Graphics: WebRender component (CVE-2026-6750)
  • firefox: thunderbird: Uninitialized memory in the Audio/Video: Web Codecs component (CVE-2026-6748)
  • firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (CVE-2026-6785)
  • firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-6771)
  • firefox: thunderbird: Incorrect boundary conditions in the DOM: Device Interfaces component (CVE-2026-6764)
  • firefox: thunderbird: Information disclosure in the Form Autofill component (CVE-2026-6765)
  • firefox: thunderbird: Privilege escalation in the Debugger component (CVE-2026-6769)
  • firefox: thunderbird: Uninitialized memory in the Audio/Video: Web Codecs component (CVE-2026-6751)
  • firefox: thunderbird: Incorrect boundary conditions in the WebRTC: Networking component (CVE-2026-6776)
  • firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-6746)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
firefox-140.10.0-1.el9_8.x86_64
firefox-x11-140.10.0-1.el9_8.x86_64
firefox-140.10.0-1.el9_8.s390x
firefox-x11-140.10.0-1.el9_8.s390x
firefox-140.10.0-1.el9_8.ppc64le
firefox-x11-140.10.0-1.el9_8.ppc64le
firefox-140.10.0-1.el9_8.aarch64
firefox-x11-140.10.0-1.el9_8.aarch64

Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from AlmaLinux/updates

All issues in AlmaLinux/updates

Similar issues

More Release issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.