CVE-2026-2447: Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, and Firefox ESR < 115.32.1.
Other sources
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 147.0.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.32.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.7.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.7.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 147.0.2 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 147.0.4 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.7.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.32.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.7.2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 147.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2447?
CVE-2026-2447 has a high severity due to the potential for heap buffer overflow leading to denial of service or code execution.
How do I fix CVE-2026-2447?
To fix CVE-2026-2447, update to Firefox version 147.0.4 or the appropriate Firefox ESR versions 140.7.1 or 115.32.1.
Which versions of Firefox are affected by CVE-2026-2447?
CVE-2026-2447 affects Firefox versions prior to 147.0.4 and Firefox ESR versions prior to 140.7.1 and 115.32.1.
What causes the vulnerability identified as CVE-2026-2447?
CVE-2026-2447 is caused by a heap buffer overflow in the libvpx library utilized by affected versions of Firefox.
Is there a known exploit for CVE-2026-2447?
As of now, there are no publicly verified exploits for CVE-2026-2447, but the vulnerability's high severity warrants immediate action.