REDHAT-BUG-2517868: Use After Free
Published Aug 18, 2026
·Updated
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Affected Software
1 affected component
Mozilla Firefox<154, <140.14, <153.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefox (Core & HTML component)to a version that resolves this vulnerability.Fixed in 154 - Upgrade
Upgrade
Mozilla Firefox ESR (Core & HTML component)to a version that resolves this vulnerability.Fixed in 140.14 - Upgrade
Upgrade
Mozilla Firefox ESR (Core & HTML component)to a version that resolves this vulnerability.Fixed in 153.1
Event History
Aug 18, 2026
Data Sourced
via Red Hat·12:56 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which Firefox releases contain the fix?
The vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
2
What type of flaw is involved?
This is a use-after-free vulnerability in Firefox's DOM: Core & HTML component, classified as CWE-416.