CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.35 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150 - Upgrade
Upgrade
Mozilla NSS (Libraries component)to a version that resolves this vulnerability.Fixed in Firefox 150 - Upgrade
Upgrade
Mozilla NSS (Libraries component)to a version that resolves this vulnerability.Fixed in Firefox ESR 115.35 - Upgrade
Upgrade
Mozilla NSS (Libraries component)to a version that resolves this vulnerability.Fixed in Firefox ESR 140.10 - Upgrade
Upgrade
Mozilla NSS (Libraries component)to a version that resolves this vulnerability.Fixed in Thunderbird 150 - Upgrade
Upgrade
Mozilla NSS (Libraries component)to a version that resolves this vulnerability.Fixed in Thunderbird 140.10
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-6746
- CVE-2026-6749
- CVE-2026-6750
- CVE-2026-6752
- CVE-2026-6754
- CVE-2026-2781
- CVE-2026-6762
- CVE-2026-6767
- CVE-2026-6772
- CVE-2026-6785
- CVE-2026-6747
- CVE-2026-6748
- CVE-2026-6751
- CVE-2026-6753
- CVE-2026-6757
- CVE-2026-6759
- CVE-2026-6761
- CVE-2026-6763
- CVE-2026-6764
- CVE-2026-6765
- CVE-2026-6766
- CVE-2026-6769
- CVE-2026-6770
- CVE-2026-6771
- CVE-2026-6776
- CVE-2026-6786
- CVE-2026-6755
- CVE-2026-6758
- CVE-2026-6760
- CVE-2026-6768
- CVE-2026-6773
- CVE-2026-6774
- CVE-2026-6775
- CVE-2026-6777
- CVE-2026-6778
- CVE-2026-6779
- CVE-2026-6780
- CVE-2026-6781
- CVE-2026-6782
- CVE-2026-6783
- CVE-2026-7321
- CVE-2026-8091
- CVE-2026-6784
- CVE-2026-6756
Frequently Asked Questions
What is the severity of CVE-2026-6772?
CVE-2026-6772 is classified with a severity level that indicates it may allow for potential security risks due to incorrect boundary conditions.
How do I fix CVE-2026-6772?
To fix CVE-2026-6772, upgrade your Mozilla Firefox or Thunderbird to versions 150, Firefox ESR 115.35, or Firefox ESR 140.10 or later.
Which versions of software are affected by CVE-2026-6772?
Affected software versions include Firefox versions prior to 150, and Thunderbird and Firefox ESR versions prior to 115.35 and 140.10.
Is CVE-2026-6772 fixed in the latest versions?
Yes, CVE-2026-6772 has been fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
What types of products does CVE-2026-6772 affect?
CVE-2026-6772 affects Mozilla Firefox, Mozilla Firefox ESR, and Mozilla Thunderbird products.