CVE-2026-2447
published 2026-02-16CVE-2026-2447: Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.60%
44.6th percentile
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 147.0.4-1 (sid) | firefox 147.0.4-1 (sid) |
| debian | firefox-esr | < firefox 147.0.4-1 (sid) | firefox 147.0.4-1 (sid) |
| debian | libvpx | < firefox 147.0.4-1 (sid) | firefox 147.0.4-1 (sid) |
| debian | thunderbird | < firefox 147.0.4-1 (sid) | firefox 147.0.4-1 (sid) |
| mozilla | firefox | < 115.32.1 | 115.32.1 |
| mozilla | firefox | < 147.0.4 | 147.0.4 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 116.0 < 140.7.1 | 140.7.1 |
| mozilla | thunderbird | < 140.7.2 | 140.7.2 |
| mozilla | thunderbird | >= 0 < 1:140.8.0esr-1 | 1:140.8.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:140.8.0esr-1 | 1:140.8.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:140.8.0esr-1 | 1:140.8.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:140.8.0esr-1 | 1:140.8.0esr-1 |
| mozilla | thunderbird | >= 141.0 < 147.0.2 | 147.0.2 |
| webmproject | libvpx | >= 0 < 1.9.0-1+deb11u5 | 1.9.0-1+deb11u5 |
| webmproject | libvpx | >= 0 < 1.12.0-1+deb12u5 | 1.12.0-1+deb12u5 |
| webmproject | libvpx | >= 0 < 1.15.0-2.1+deb13u1 | 1.15.0-2.1+deb13u1 |
| webmproject | libvpx | >= 0 < 1.16.0-3 | 1.16.0-3 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvpx vulnerability
vendor_ubuntu·2026-02-19
CVE-2026-2447 libvpx vulnerability
Title: libvpx vulnerability
Summary: libvpx could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that libvpx did not properly handle certain malformed
media files. If an application using libvpx opened a specially crafted
file, a remote attacker could cause a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvpx: Heap buffer overflow in libvpx
vendor_redhat·2026-02-16·CVSS 8.8
CVE-2026-2447 [HIGH] libvpx: Heap buffer overflow in libvpx
libvpx: Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Heap buffer overflow in libvpx.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux
Debian
CVE-2026-2447: firefox - Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Fi...
vendor_debian·2026·CVSS 8.8
CVE-2026-2447 [HIGH] CVE-2026-2447: firefox - Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Fi...
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.
Scope: local
sid: resolved (fixed in 147.0.4-1)
Mozilla
Mozilla Foundation Security Advisory 2026-10: CVE-2026-2447
vendor_mozilla·CVSS 8.8
CVE-2026-2447 [HIGH] Mozilla Foundation Security Advisory 2026-10: CVE-2026-2447
Mozilla Foundation Security Advisory 2026-10
CVE: CVE-2026-2447
Product: Firefox, Firefox ESR
Impact: high
Fixed in: Firefox 147.0.4
Firefox ESR 115.32.1
Firefox ESR 140.7.1
Mozilla
Mozilla Foundation Security Advisory 2026-11: CVE-2026-2447
vendor_mozilla·CVSS 8.8
CVE-2026-2447 [HIGH] Mozilla Foundation Security Advisory 2026-11: CVE-2026-2447
Mozilla Foundation Security Advisory 2026-11
CVE: CVE-2026-2447
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.7.2
Thunderbird 147.0.2
VulDB
Mozilla Firefox up to 147.0.3 libvpx heap-based overflow (EUVD-2026-6081 / Nessus ID 299214)
vuldb·2026-07-01·CVSS 8.8
CVE-2026-2447 [HIGH] Mozilla Firefox up to 147.0.3 libvpx heap-based overflow (EUVD-2026-6081 / Nessus ID 299214)
A vulnerability was found in Mozilla Firefox up to 147.0.3 and classified as critical. This issue affects some unknown processing of the component libvpx. Such manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2026-2447. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
OSV
CVE-2026-2447: Heap buffer overflow in libvpx
osv·2026-02-16·CVSS 8.8
CVE-2026-2447 [HIGH] CVE-2026-2447: Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.
GHSA
GHSA-c99q-x737-hc5j: Heap buffer overflow in libvpx
ghsa_unreviewed·2026-02-16
CVE-2026-2447 [HIGH] CWE-122 GHSA-c99q-x737-hc5j: Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, and Firefox ESR < 115.32.1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-2447 libvpx: Heap buffer overflow in libvpx [fedora-all]
bugzilla·2026-02-17·CVSS 8.8
CVE-2026-2447 [HIGH] CVE-2026-2447 libvpx: Heap buffer overflow in libvpx [fedora-all]
CVE-2026-2447 libvpx: Heap buffer overflow in libvpx [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
firefox uses system libvpx ("--with-system-libvpx" in about:buildconfig); any chance we can get this package updated to address this issue?
Bugzilla
CVE-2026-2447 libvpx: Heap buffer overflow in libvpx
bugzilla·2026-02-16·CVSS 8.8
CVE-2026-2447 [HIGH] CVE-2026-2447 libvpx: Heap buffer overflow in libvpx
CVE-2026-2447 libvpx: Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, and Firefox ESR < 115.32.1.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:3338 https://access.redhat.com/errata/RHSA-2026:3338
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:3339 https://access.redhat.com/errata/RHSA-2026:3339
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:3361 https://access.redhat.com/errata/RHSA-2026:3361
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Suppo
Wiz
CVE-2026-2447 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2447 [HIGH] CVE-2026-2447 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2447 :
NixOS vulnerability analysis and mitigation
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.
Source : NVD
## 8.8
Score
Published February 16, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
NixOS
Mozilla Firefox
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
MozillaThunderbird-openpgp-librnp
MozillaThunderbird-translations-common
Sources
AlmaLinux 8 Severity HIGH Has Fix Added at: Mar 03, 2026
AlmaLinux 9 Severity HIGH Has Fix Added at: Mar 02, 2026
Chaing
https://bugzilla.mozilla.org/show_bug.cgi?id=2014390https://www.mozilla.org/security/advisories/mfsa2026-10/https://www.mozilla.org/security/advisories/mfsa2026-11/https://lists.debian.org/debian-lts-announce/2026/02/msg00028.htmlhttps://access.redhat.com/errata/RHSA-2026:16174https://access.redhat.com/errata/RHSA-2026:3338https://access.redhat.com/errata/RHSA-2026:3339https://access.redhat.com/errata/RHSA-2026:3361https://access.redhat.com/errata/RHSA-2026:3491https://access.redhat.com/errata/RHSA-2026:3492https://access.redhat.com/errata/RHSA-2026:3493https://access.redhat.com/errata/RHSA-2026:3494https://access.redhat.com/errata/RHSA-2026:3495https://access.redhat.com/errata/RHSA-2026:3496https://access.redhat.com/errata/RHSA-2026:3497https://access.redhat.com/errata/RHSA-2026:3515https://access.redhat.com/errata/RHSA-2026:3516https://access.redhat.com/errata/RHSA-2026:3517https://access.redhat.com/errata/RHSA-2026:3967https://access.redhat.com/errata/RHSA-2026:3976https://access.redhat.com/errata/RHSA-2026:3978https://access.redhat.com/errata/RHSA-2026:3979https://access.redhat.com/errata/RHSA-2026:3980https://access.redhat.com/errata/RHSA-2026:3981https://access.redhat.com/errata/RHSA-2026:3982https://access.redhat.com/errata/RHSA-2026:3983https://access.redhat.com/errata/RHSA-2026:3984https://access.redhat.com/errata/RHSA-2026:4022https://access.redhat.com/errata/RHSA-2026:4152https://access.redhat.com/errata/RHSA-2026:4260https://access.redhat.com/errata/RHSA-2026:4432https://access.redhat.com/errata/RHSA-2026:4447https://access.redhat.com/errata/RHSA-2026:4629https://access.redhat.com/errata/RHSA-2026:5227https://access.redhat.com/errata/RHSA-2026:5228https://access.redhat.com/errata/RHSA-2026:5229https://access.redhat.com/errata/RHSA-2026:5230https://access.redhat.com/errata/RHSA-2026:5231https://access.redhat.com/errata/RHSA-2026:5319https://access.redhat.com/errata/RHSA-2026:5320https://access.redhat.com/errata/RHSA-2026:5323https://access.redhat.com/errata/RHSA-2026:5324https://access.redhat.com/errata/RHSA-2026:5326https://access.redhat.com/errata/RHSA-2026:8746https://access.redhat.com/errata/RHSA-2026:8747https://access.redhat.com/errata/RHSA-2026:8748https://access.redhat.com/security/cve/CVE-2026-2447https://bugzilla.redhat.com/show_bug.cgi?id=2440219https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2447.json
2026-02-16
Published