REDHAT-BUG-2517846: Use After Free
Published Aug 18, 2026
·Updated
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Affected Software
2 affected components
Mozilla Firefox<154
Mozilla Firefox ESR>=115.0<=115.38, >=140.0<=140.13, >=153.0<=153.0, >=153.1<=153.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 154 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.39 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.14 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 153.1
Event History
Aug 18, 2026
Data Sourced
via Red Hat·12:54 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which Firefox releases contain the fix?
The vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
2
What component is affected?
The issue affects the Layout: Text and Fonts component and is classified as a use-after-free vulnerability.