REDHAT-BUG-2489218: High severity Mozilla Firefox ESR vulnerability
Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.12 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.37 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 152 - Upgrade
Upgrade
Mozilla Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.12 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 152
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2489218?
The severity of REDHAT-BUG-2489218 is considered high, rated at 7.
How do I fix REDHAT-BUG-2489218?
To fix REDHAT-BUG-2489218, update to the latest versions of Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152, or Thunderbird 152.
What software is affected by REDHAT-BUG-2489218?
The affected software includes Mozilla Firefox ESR 115.36, 140.11, Mozilla Thunderbird ESR 140.11, Mozilla Firefox 151, and Mozilla Thunderbird 151.
Can REDHAT-BUG-2489218 be exploited?
Yes, some memory safety bugs in REDHAT-BUG-2489218 showed evidence of potential memory corruption that could be exploited to run arbitrary code.
When was REDHAT-BUG-2489218 published?
REDHAT-BUG-2489218 was published on June 16, 2026.