REDHAT-BUG-2460096: High severity Mozilla Firefox vulnerability
Published Apr 21, 2026
·Updated
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, and Firefox ESR 140.10.
Affected Software
3 affected components
Mozilla Firefox<150
Mozilla Firefox ESR 115<115.35
Mozilla Firefox ESR 140<140.10
Event History
Apr 21, 2026
Data Sourced
via Red Hat·02:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2460096?
The severity of REDHAT-BUG-2460096 is categorized as high due to potential information disclosure risks.
2
How do I fix REDHAT-BUG-2460096?
To fix REDHAT-BUG-2460096, you must update to Firefox 150, Firefox ESR 115.35, or Firefox ESR 140.10.
3
What software is affected by REDHAT-BUG-2460096?
The affected software includes Mozilla Firefox versions up to 150, and Mozilla Firefox ESR versions up to 115.35 and 140.10.
4
What kind of vulnerability is REDHAT-BUG-2460096?
REDHAT-BUG-2460096 is an information disclosure vulnerability caused by uninitialized memory in the Graphics: Canvas2D component.
5
When was REDHAT-BUG-2460096 fixed?
REDHAT-BUG-2460096 was fixed in versions Firefox 150, Firefox ESR 115.35, and Firefox ESR 140.10.