CVE-2026-7323: Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1
Memory safety bugs present in Firefox ESR 140.10.0 and Firefox 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Other sources
Memory safety bugs present in Firefox ESR 140.10.0, Thunderbird ESR 140.10.0, Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Firefox ESR 140.10.1.
— Red Hat
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.10.1 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.10.1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 150.0.1 - Upgrade
Upgrade
Mozilla Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.10.1 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 150.0.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-7323?
CVE-2026-7323 is classified as a high severity vulnerability that can potentially allow arbitrary code execution.
How do I fix CVE-2026-7323?
To fix CVE-2026-7323, users should update to Mozilla Firefox ESR version 140.10.1 or Firefox version 150.0.1.
Which versions of software are affected by CVE-2026-7323?
CVE-2026-7323 affects Mozilla Firefox ESR version 140.10.0 and Firefox version 150.0.0.
What types of vulnerabilities are associated with CVE-2026-7323?
CVE-2026-7323 is associated with memory safety bugs that may lead to memory corruption.
Is there a workaround for CVE-2026-7323 until I can update?
There are no documented workarounds for CVE-2026-7323, so updating to the patched versions is recommended.