CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Graphics: Text component
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability affects Firefox < 149.0.2 and Firefox ESR < 140.9.1.
Other sources
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.9.1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 149.0.2 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.9.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 149.0.2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.9.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.