PT-2026-8351 · Libvpx+5 · Libvpx+7

Jayjayjazz

·

Published

2026-01-01

·

Updated

2026-04-17

·

CVE-2026-2447

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 147.0.4 Firefox ESR versions prior to 140.7.1 Firefox ESR versions prior to 115.32.1 Thunderbird versions prior to 140.7.2 Thunderbird versions prior to 147.0.2
Description A heap buffer overflow exists in the libvpx VP8/VP9 video codec path. This issue could be triggered by crafted media, potentially leading to memory corruption and remote code execution. The vulnerability affects global browser users. The issue is related to the libvpx library and specifically impacts the VP9 video processing functionality.
Recommendations Update Firefox to version 147.0.4 or later. Update Firefox ESR to version 140.7.1 or later. Update Firefox ESR to version 115.32.1 or later. Update Thunderbird to version 140.7.2 or later. Update Thunderbird to version 147.0.2 or later.

Fix

RCE

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2026:3338
ALSA-2026:3339
ALSA-2026:3361
ALSA-2026:3515
ALSA-2026:3516
ALSA-2026:3517
ALSA-2026:3967
ALSA-2026:4447
ALSA-2026:4629
BDU:2026-02014
CVE-2026-2447
ECHO-F542-A708-8974
MGASA-2026-0044
OESA-2026-1451
OESA-2026-1468
OESA-2026-1471
OESA-2026-1539
OPENSUSE-SU-2026:10212-1
OPENSUSE-SU-2026:10218-1
OPENSUSE-SU-2026:10225-1
OPENSUSE-SU-2026:20253-1
OPENSUSE-SU-2026:20391-1
RHSA-2026:3338
RHSA-2026:3339
RHSA-2026:3361
RHSA-2026:3491
RHSA-2026:3492
RHSA-2026:3493
RHSA-2026:3494
RHSA-2026:3495
RHSA-2026:3496
RHSA-2026:3497
RHSA-2026:3515
RHSA-2026:3516
RHSA-2026:3517
RHSA-2026:3967
RHSA-2026:3976
RHSA-2026:3978
RHSA-2026:3979
RHSA-2026:3980
RHSA-2026:3981
RHSA-2026:3982
RHSA-2026:3983
RHSA-2026:3984
RHSA-2026:4022
RHSA-2026:4152
RHSA-2026:4260
RHSA-2026:4432
RHSA-2026:4447
RHSA-2026:4629
RHSA-2026:5227
RHSA-2026:5228
RHSA-2026:5229
RHSA-2026:5230
RHSA-2026:5231
RHSA-2026:5319
RHSA-2026:5320
RHSA-2026:5323
RHSA-2026:5324
RHSA-2026:5326
SUSE-SU-2026:0602-1
SUSE-SU-2026:0611-1
SUSE-SU-2026:0692-1
SUSE-SU-2026:20582-1
USN-8053-1

Affected Products

Firefox
Firefox Esr
Linuxmint
Red Os
Rocky Linux
Thunderbird
Ubuntu
Libvpx