firefox-140.10.1-1.el8_10.ML.1
エラータID: AXSA:2026-744:11
リリース日:
2026/06/02 Tuesday - 09:58
題名:
firefox-140.10.1-1.el8_10.ML.1
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Firefox および Thunderbird には、メモリ領域の範囲外読み取りの
問題があるため、リモートの攻撃者により、情報の漏洩、データ破壊、
およびサービス拒否攻撃を可能とする脆弱性が存在します。
(CVE-2026-7320)
- Firefox および Thunderbird には、メモリ領域の範囲外読み取りの
問題があるため、リモートの攻撃者により、情報の漏洩、およびデータ
破壊を可能とする脆弱性が存在します。(CVE-2026-7321)
- Firefox および Thunderbird には、リモートの攻撃者により、
メモリ破壊、任意のコードの実行を可能とする脆弱性が存在します。
(CVE-2026-7322)
- Firefox および Thunderbird には、リモートの攻撃者により、
メモリ破壊、および任意のコードの実行を可能とする脆弱性が存在します。
(CVE-2026-7323)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-7320
Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
CVE-2026-7321
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.
CVE-2026-7322
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
CVE-2026-7323
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
追加情報:
N/A
ダウンロード:
SRPMS
- firefox-140.10.1-1.el8_10.ML.1.src.rpm
MD5: a2c17b7dcaa7f61933f7276baec6ef0e
SHA-256: 16112f680a1edaefc32bfd2fc2986bde9a0cc1e9af4a7ce3f5c395ec03bec829
Size: 0.99 GB
Asianux Server 8 for x86_64
- firefox-140.10.1-1.el8_10.ML.1.x86_64.rpm
MD5: eb129354dadd4121e78cad780ca30bfa
SHA-256: c993c089a5f6df4060ebd407e1ed63bbf07befc5dd9f6fdc8264204c611d49d4
Size: 119.03 MB