RHEL 9 : firefox (RHSA-2026:27734)

critical Nessus Plugin ID 321898

Synopsis

The remote Red Hat host is missing one or more security updates for firefox.

Description

The remote Redhat Enterprise Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2026:27734 advisory.

Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.

Security Fix(es):

* firefox: thunderbird: Sandbox escape in the DOM: Workers component (CVE-2026-12294)

* firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12313)

* firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12311)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12290)

* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12327)

* firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component (CVE-2026-12299)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12329)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12312)

* firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12302)

* firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12328)

* firefox: thunderbird: Incorrect boundary conditions in the Internationalization component (CVE-2026-12330)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12314)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12309)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12310)

* firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component (CVE-2026-12325)

* firefox: thunderbird: Sandbox escape in the DOM: Navigation component (CVE-2026-12295)

* firefox: thunderbird: Privilege escalation in the Graphics: WebRender component (CVE-2026-12289)

* firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12315)

* firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component (CVE-2026-12296)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12306)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12307)

* firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component (CVE-2026-12297)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12305)

* firefox: thunderbird: Incorrect boundary conditions in the Web Audio component (CVE-2026-12292)

* firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12308)

* firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-12324)

* firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-12304)

* firefox: thunderbird: Use-after-free in the Networking: HTTP component (CVE-2026-12291)

* firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 (CVE-2026-12298)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL firefox package based on the guidance in RHSA-2026:27734.

See Also

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2489207

https://bugzilla.redhat.com/show_bug.cgi?id=2489208

https://bugzilla.redhat.com/show_bug.cgi?id=2489209

https://bugzilla.redhat.com/show_bug.cgi?id=2489210

https://bugzilla.redhat.com/show_bug.cgi?id=2489211

https://bugzilla.redhat.com/show_bug.cgi?id=2489212

https://bugzilla.redhat.com/show_bug.cgi?id=2489214

https://bugzilla.redhat.com/show_bug.cgi?id=2489215

https://bugzilla.redhat.com/show_bug.cgi?id=2489217

https://bugzilla.redhat.com/show_bug.cgi?id=2489218

https://bugzilla.redhat.com/show_bug.cgi?id=2489220

https://bugzilla.redhat.com/show_bug.cgi?id=2489221

https://bugzilla.redhat.com/show_bug.cgi?id=2489223

https://bugzilla.redhat.com/show_bug.cgi?id=2489224

https://bugzilla.redhat.com/show_bug.cgi?id=2489225

https://bugzilla.redhat.com/show_bug.cgi?id=2489226

https://bugzilla.redhat.com/show_bug.cgi?id=2489229

https://bugzilla.redhat.com/show_bug.cgi?id=2489231

https://bugzilla.redhat.com/show_bug.cgi?id=2489232

https://bugzilla.redhat.com/show_bug.cgi?id=2489233

https://bugzilla.redhat.com/show_bug.cgi?id=2489234

https://bugzilla.redhat.com/show_bug.cgi?id=2489235

https://bugzilla.redhat.com/show_bug.cgi?id=2489236

https://bugzilla.redhat.com/show_bug.cgi?id=2489237

https://bugzilla.redhat.com/show_bug.cgi?id=2489239

https://bugzilla.redhat.com/show_bug.cgi?id=2489240

https://bugzilla.redhat.com/show_bug.cgi?id=2489243

https://bugzilla.redhat.com/show_bug.cgi?id=2489244

https://bugzilla.redhat.com/show_bug.cgi?id=2489248

http://www.nessus.org/u?b1153110

https://access.redhat.com/errata/RHSA-2026:27734

Plugin Details

Severity: Critical

ID: 321898

File Name: redhat-RHSA-2026-27734.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 6/22/2026

Updated: 6/22/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.1

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-12297

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:redhat:rhel_eus:9.8, p-cpe:/a:redhat:enterprise_linux:firefox, p-cpe:/a:redhat:enterprise_linux:firefox-x11, cpe:/o:redhat:enterprise_linux:9

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 6/22/2026

Vulnerability Publication Date: 6/15/2026

Reference Information

CVE: CVE-2026-12289, CVE-2026-12290, CVE-2026-12291, CVE-2026-12292, CVE-2026-12294, CVE-2026-12295, CVE-2026-12296, CVE-2026-12297, CVE-2026-12298, CVE-2026-12299, CVE-2026-12302, CVE-2026-12304, CVE-2026-12305, CVE-2026-12306, CVE-2026-12307, CVE-2026-12308, CVE-2026-12309, CVE-2026-12310, CVE-2026-12311, CVE-2026-12312, CVE-2026-12313, CVE-2026-12314, CVE-2026-12315, CVE-2026-12324, CVE-2026-12325, CVE-2026-12327, CVE-2026-12328, CVE-2026-12329, CVE-2026-12330

CWE: 1286, 131, 243, 266, 346, 403, 653, 733, 787, 807, 823, 825, 843

RHSA: 2026:27734