PT-2026-33934 · Mozilla+1 · Firefox+2

Inseo An

·

Published

2026-04-21

·

Updated

2026-05-19

·

CVE-2026-6748

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 150 Firefox ESR versions prior to 140.10 Thunderbird versions prior to 150 Thunderbird versions prior to 140.10
Description Uninitialized memory exists in the Audio/Video: Web Codecs component.
Recommendations Update to version 150 Update to version 140.10 Update to version 150 Update to version 140.10

Fix

DoS

Weakness Enumeration

Related Identifiers

ALSA-2026:10757
ALSA-2026:10766
ALSA-2026:10767
ALSA-2026:12285
ALSA-2026:13537
ALSA-2026:15892
ALSA-2026:19348
CVE-2026-6748
OESA-2026-2105
OESA-2026-2106
OESA-2026-2107
OESA-2026-2108
OESA-2026-2109
OPENSUSE-SU-2026:10610-1
OPENSUSE-SU-2026:10626-1
RHSA-2026:10757
RHSA-2026:10766
RHSA-2026:10767
RHSA-2026:19348

Affected Products

Firefox
Rocky Linux
Thunderbird