RHSA-2022:0824: Critical: firefox security and bug fix update
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.<br>This update upgrades Firefox to version 91.7.0 ESR.<br>Security Fix(es):<br><li> Mozilla: Use-after-free in XSLT parameter processing (CVE-2022-26485)</li> <li> Mozilla: Use-after-free in WebGPU IPC Framework (CVE-2022-26486)</li> <li> expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235)</li> <li> expat: Namespace-separator characters in "xmlns[:prefix]" attribute values can lead to arbitrary code execution (CVE-2022-25236)</li> <li> expat: Integer overflow in storeRawNames() (CVE-2022-25315)</li> <li> Mozilla: Use-after-free in text reflows (CVE-2022-26381)</li> <li> Mozilla: Browser window spoof using fullscreen mode (CVE-2022-26383)</li> <li> Mozilla: iframe allow-scripts sandbox bypass (CVE-2022-26384)</li> <li> Mozilla: Time-of-check time-of-use bug when verifying add-on signatures (CVE-2022-26387)</li> <li> Mozilla: Temporary files downloaded to /tmp and accessible by other local users (CVE-2022-26386)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> Firefox 91.3.0-1 Language packs installed at /usr/lib64/firefox/langpacks cannot be used any more (BZ#2030190)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the main security fixes in RHSA-2022:0824?
RHSA-2022:0824 addresses a use-after-free vulnerability in XSLT parameter processing identified as CVE-2022-26485.
What is the severity of RHSA-2022:0824?
The severity of RHSA-2022:0824 is classified as moderate.
How do I fix RHSA-2022:0824?
To fix RHSA-2022:0824, upgrade Firefox to version 91.7.0 ESR.
Which versions of Firefox are affected by RHSA-2022:0824?
RHSA-2022:0824 affects Firefox versions prior to 91.7.0-3.el7_9.
Is there a specific package for debugging related to RHSA-2022:0824?
Yes, the firefox-debuginfo package also has updates related to RHSA-2022:0824.