Re: [BLFS Trac] #23111: firefox-140.11.0esr and js-140.11.0 (spidermonkey)
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23111: firefox-140.11.0esr and js-140.11.0 (spidermonkey)
-------------------------+-------------------------------
Reporter: (none) | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-------------------------------
Comment (by Joe Locash):
Security fixes for 140.11.0ESR:
- CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web
Codecs component (high)
- CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine:
JIT component (high)
- CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component
(high)
- CVE-2026-8391: Other issue in the JavaScript Engine component (high)
- CVE-2026-8401: Sandbox escape in the Profile Backup component (high)
- CVE-2026-8949: Integer overflow in the Widget: Win32 component
(moderate)
- CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP
component (moderate)
- CVE-2026-8953: Sandbox escape due to use-after-free in the Disability
Access APIs component(moderate)
- CVE-2026-8954: Incorrect boundary conditions, integer overflow in the
Audio/Video component (moderate)
- CVE-2026-8955: Privilege escalation in the DOM: Workers component
(moderate)
- CVE-2026-8956: Integer overflow in the Networking: JAR component
(moderate)
- CVE-2026-8957: Privilege escalation in the Enterprise Policies
component (moderate)
- CVE-2026-8958: Information disclosure, sandbox escape in the Security:
Process Sandboxing component (moderate)
- CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in
the Widget: Win32 component (moderate)
- CVE-2026-8961: Spoofing issue in the Form Autofill component (low)
- CVE-2026-8962: Mitigation bypass in the DOM: Security component (low)
- CVE-2026-8968: Denial-of-service due to invalid pointer in the
Audio/Video: Web Codecs component(low)
- CVE-2026-8970: Privilege escalation in the Security component (low)
- CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and
Firefox 151 (moderate)
- CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox
ESR 140.11 and Firefox 151 (hight)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-48/
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23111#comment:14>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page