Home

Description

Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.

PUBLISHED Reserved 2026-04-07 | Published 2026-04-07 | Updated 2026-04-13 | Assigner mozilla

Product status

140.9.1 (rpm)
unaffected

149.0.2 (rpm)
unaffected

140.9.1 (rpm)
unaffected

149.0.2 (rpm)
unaffected

Credits

Sajeeb Lohani

References

bugzilla.mozilla.org/show_bug.cgi?id=2017867

www.mozilla.org/security/advisories/mfsa2026-25/

www.mozilla.org/security/advisories/mfsa2026-27/

www.mozilla.org/security/advisories/mfsa2026-28/

www.mozilla.org/security/advisories/mfsa2026-29/

cve.org (CVE-2026-5732)

nvd.nist.gov (CVE-2026-5732)

Download JSON