Executive brief
A vulnerability exists in the graphics rendering component of Mozilla Firefox and Thunderbird. This component is responsible for drawing 2D graphics on web pages and in emails. An exploit could allow an attacker to cause the application to crash or behave unexpectedly, potentially leading to a denial of service for the user.
Technical details
A vulnerability classified as 'Incorrect Boundary Conditions' (CWE-754) and 'Out-of-bounds Write' (CWE-787) exists in the Graphics: Canvas2D component of Mozilla browsers and mail clients. The flaw occurs when the application fails to properly validate the boundaries of memory buffers during 2D graphics operations. A remote, unauthenticated attacker can exploit this by providing specially crafted web content or emails. Successful exploitation can lead to memory corruption, resulting in a denial of service (application crash) or potentially arbitrary code execution. The issue is fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Affected products
- Mozilla Firefox < 149
- Mozilla Firefox ESR < 115.34, < 140.9
- Mozilla Thunderbird < 149, < 140.9
Timeline
- 2026-03-24: disclosed
- 2026-03-24: advisory
- 2026-03-24: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2016349
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-21/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930