[CLSA-2026:1784826792] firefox: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-23 17:13:42 UTC
Description:
- CVE-2024-0747: Document::Open inheriting CSP from a different window - CVE-2024-0749: Phishing site popup could obscure the address bar - CVE-2025-5268: Memory safety bugs (gfxFont mHasSpaceFeatures atomicity, PresShell event-handler UAF, wasm uncheckedReadValType missing types)
Updated packages:
  • firefox-115.4.0-1.el9_2.alma.1.tuxcare.els1.x86_64.rpm
    sha:f8126bd97dcb69ba5efcde5ba42910fc8bd7e256d73f04910356ce1920e4be6e
  • firefox-x11-115.4.0-1.el9_2.alma.1.tuxcare.els1.x86_64.rpm
    sha:03cc9086116d760c79ac690bf184f7cdd2fa212d7814dfc4d54544cac4e3e04b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.