Red Hat released multiple Firefox security advisories for RHEL 7 and several RHEL 8 support channels, upgrading the browser to Firefox 115.11.0 ESR to remediate six Mozilla flaws. The updates cover product streams including RHEL 7 variants and RHEL 8.2, 8.4, and 8.10 across architectures such as x86_64, ppc64le, s390x, and aarch64, with severity ratings ranging from Important to Moderate depending on the platform and channel.
The patched issues include CVE-2024-4777, a set of memory safety bugs that Mozilla said showed evidence of memory corruption and could potentially lead to arbitrary code execution; CVE-2024-4770, a use-after-free that could be triggered while printing or saving pages to PDF; CVE-2024-4769, a cross-origin information disclosure side channel in Web Workers; CVE-2024-4768, a clickjacking-related permissions bypass involving WebAuthn prompts; and CVE-2024-4767, which could leave IndexedDB files behind after private browsing sessions in certain configurations. Red Hat advised customers to apply prerequisite errata where required before installing the Firefox update.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
On 2024-06-10, Red Hat published RHSA-2024:3783, a Moderate Firefox security update for Red Hat Enterprise Linux 8 and 8.10 Extended Life Cycle variants across x86_64, s390x, ppc64le, and aarch64, upgrading Firefox to 115.11.0 ESR and addressing the same six vulnerabilities.
On 2024-05-20, Red Hat published RHSA-2024:2906, an Important Firefox security update for Red Hat Enterprise Linux 9.2 support channels. The advisory upgraded Firefox to 115.11.0 ESR across multiple architectures and fixed six vulnerabilities including CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, and CVE-2024-4777.
On 2024-05-16, Red Hat published RHSA-2024:2884, an Important Firefox security update for Red Hat Enterprise Linux 9.0 Extended Update Support and related service variants. The advisory upgraded Firefox to 115.11.0 ESR and fixed six vulnerabilities including CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, and CVE-2024-4777.
On 2024-05-16, Red Hat published RHSA-2024:2885, an Important Firefox security update for multiple Red Hat Enterprise Linux 8.8 support channels, upgrading Firefox to 115.11.0 ESR. The advisory addressed six vulnerabilities including CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, and CVE-2024-4777.
On 2024-05-16, Red Hat published RHSA-2024:2887, an Important Firefox security update for multiple Red Hat Enterprise Linux 8.6 support channels including EUS, AUS, TUS, ELLL, and SAP Solutions services. The advisory upgraded Firefox to 115.11.0 ESR and fixed six vulnerabilities including CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, and CVE-2024-4777.
On 2024-05-16, Red Hat published RHSA-2024:2886, an Important Firefox security update for multiple Red Hat Enterprise Linux 8.4 service channels including AUS, TUS, EUS/ELLL, and SAP update services, upgrading Firefox to 115.11.0 ESR and fixing six vulnerabilities.
On 2024-05-16, Red Hat published RHSA-2024:2882, an Important Firefox security update for Red Hat Enterprise Linux 8.2 Advanced Update Support that upgraded Firefox to 115.11.0 ESR and addressed the same six Firefox vulnerabilities.
On 2024-05-16, Red Hat published RHSA-2024:2881, an Important Firefox security update for Red Hat Enterprise Linux 7 that upgraded Firefox to 115.11.0 ESR and fixed six vulnerabilities including CVE-2024-4367, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, and CVE-2024-4777.
Mozilla disclosed CVE-2024-4777 on 2024-05-14 as a set of memory safety bugs affecting Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10; Mozilla said some bugs showed memory corruption and might enable arbitrary code execution with enough effort.
Mozilla disclosed CVE-2024-4770 on 2024-05-14 as a potential use-after-free vulnerability that could be triggered when saving a page to PDF with certain font styles.
Mozilla disclosed CVE-2024-4769 on 2024-05-14, describing an information disclosure issue in Web Workers where error handling could distinguish script from non-script cross-origin responses.
Mozilla disclosed CVE-2024-4768 on 2024-05-14 as a clickjacking-related permissions bypass issue involving popup notifications' interaction with WebAuthn that could help trick users into granting permissions.
Mozilla disclosed CVE-2024-4767 on 2024-05-14, describing a privacy issue where IndexedDB files could remain after closing a private browsing window when the browser.privatebrowsing.autostart preference was enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.