Executive brief
A vulnerability exists in the web browser and email client components responsible for processing audio and video content. An attacker could exploit this flaw to cause the application to crash or become unresponsive, potentially disrupting business operations and user productivity. This issue affects users of Firefox and Thunderbird who have not yet updated to the latest security releases.
Technical details
This vulnerability is classified as an improper check for unusual or exceptional conditions (CWE-754) and incorrect calculation of buffer size (CWE-131) within the Web Codecs component of the Audio/Video subsystem. The flaw is triggered by incorrect boundary conditions during media processing. A remote, unauthenticated attacker can exploit this over the network to cause a denial-of-service (application crash). The vulnerability was addressed by improving boundary checks in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Affected products
- Mozilla Firefox < 149
- Mozilla Firefox ESR < 140.9
- Mozilla Thunderbird < 149
- Mozilla Thunderbird ESR < 140.9
- Red Hat Enterprise Linux Server (v. 7 ELS) 7
- Red Hat Enterprise Linux AppStream EUS (v. 10.0) 10.0
Timeline
- 2026-03-24: advisory: Mozilla Foundation Security Advisory published
- 2026-03-24: patched: Fixed in Firefox 149 and Firefox ESR 140.9
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2020030
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930
- https://access.redhat.com/errata/RHSA-2026:5931