CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.11 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 151 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.11 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 151 - Upgrade
Upgrade
Thunderbird 140.11to a version that resolves this vulnerability.Fixed in 140.11
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-8945
- CVE-2026-8946
- CVE-2026-8947
- CVE-2026-8948
- CVE-2026-8949
- CVE-2026-8950
- CVE-2026-8951
- CVE-2026-8952
- CVE-2026-8953
- CVE-2026-8954
- CVE-2026-8955
- CVE-2026-8956
- CVE-2026-8957
- CVE-2026-8958
- CVE-2026-8959
- CVE-2026-8960
- CVE-2026-8961
- CVE-2026-8962
- CVE-2026-8963
- CVE-2026-8964
- CVE-2026-8965
- CVE-2026-8966
- CVE-2026-8967
- CVE-2026-8968
- CVE-2026-8969
- CVE-2026-8970
- CVE-2026-8971
- CVE-2026-8972
- CVE-2026-8973
- CVE-2026-8974
- CVE-2026-8975
- CVE-2026-8388
- CVE-2026-8391
- CVE-2026-8401
Frequently Asked Questions
What is the severity of CVE-2026-8968?
CVE-2026-8968 is classified as a denial-of-service vulnerability due to an invalid pointer in the Audio/Video: Web Codecs component.
How do I fix CVE-2026-8968?
To fix CVE-2026-8968, users should update to Firefox version 151, Firefox ESR version 140.11, Thunderbird version 151, or Thunderbird ESR version 140.11.
What are the affected software versions for CVE-2026-8968?
CVE-2026-8968 affects Mozilla Firefox versions before 151, Firefox ESR versions before 140.11, and Thunderbird versions before 151 and 140.11.
Can CVE-2026-8968 be exploited remotely?
CVE-2026-8968 can potentially be exploited remotely, leading to a denial-of-service condition.
Is there a workaround for CVE-2026-8968?
There is no official workaround for CVE-2026-8968; updating to the fixed versions is the recommended solution.