Re: [BLFS Trac] #23111: firefox-140.10.0esr and js-140.10.0 (spidermonkey)

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23111: firefox-140.10.0esr and js-140.10.0 (spidermonkey)
-------------------------+------------------------------
 Reporter:  (none)       |       Owner:  Douglas R. Reno
     Type:  enhancement  |      Status:  assigned
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------------
Comment (by Joe Locash):

 Security fixes for 140.10.0ESR:
  - CVE-2026-6746: Use-after-free in the DOM: Core & HTML component (high)
  - CVE-2026-6747: Use-after-free in the WebRTC component (high)
  - CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs
 component (high)
  - CVE-2026-6749: Information disclosure due to uninitialized memory in
 the Graphics: Canvas2D component (high)
  - CVE-2026-6750: Privilege escalation in the Graphics: WebRender
 component (high)
  - CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs
 component (high)
  - CVE-2026-6752: Incorrect boundary conditions in the WebRTC component
 (high)
  - CVE-2026-6753: Incorrect boundary conditions in the WebRTC component
 (high)
  - CVE-2026-6754: Use-after-free in the JavaScript Engine component (high)
  - CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component
 (moderate)
  - CVE-2026-6759: Use-after-free in the Widget: Cocoa component (moderate)
  - CVE-2026-6761: Privilege escalation in the Networking component
 (moderate)
  - CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component
 (moderate)
  - CVE-2026-6763: Mitigation bypass in the File Handling component
 (moderate)
  - CVE-2026-6764: Incorrect boundary conditions in the DOM: Device
 Interfaces component (moderate)
  - CVE-2026-6765: Information disclosure in the Form Autofill component
 (moderate)
  - CVE-2026-6766: Incorrect boundary conditions in the Libraries component
 in NSS (moderate)
  - CVE-2026-6767: Other issue in the Libraries component in NSS (moderate)
  - CVE-2026-6769: Privilege escalation in the Debugger component
 (moderate)
  - CVE-2026-6770: Other issue in the Storage: IndexedDB component
 (moderate)
  - CVE-2026-6771: Mitigation bypass in the DOM: Security component
 (moderate)
  - CVE-2026-6772: Incorrect boundary conditions in the Libraries component
 in NSS (moderate)
  - CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking
 component (moderate)
  - CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox
 ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (high)
  - CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10,
 Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (high)

 https://www.mozilla.org/en-US/security/advisories/mfsa2026-32/
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23111#comment:5>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.