Re: [BLFS Trac] #23111: firefox-140.11.0esr and js-140.11.0 (spidermonkey)

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23111: firefox-140.11.0esr and js-140.11.0 (spidermonkey)
-------------------------+-------------------------------
 Reporter:  (none)       |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Comment (by Joe Locash):

 Security fixes for 140.11.0ESR:
  - CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web
 Codecs component (high)
  - CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine:
 JIT component (high)
  - CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component
 (high)
  - CVE-2026-8391: Other issue in the JavaScript Engine component (high)
  - CVE-2026-8401: Sandbox escape in the Profile Backup component (high)
  - CVE-2026-8949: Integer overflow in the Widget: Win32 component
 (moderate)
  - CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP
 component (moderate)
  - CVE-2026-8953: Sandbox escape due to use-after-free in the Disability
 Access APIs component(moderate)
  - CVE-2026-8954: Incorrect boundary conditions, integer overflow in the
 Audio/Video component (moderate)
  - CVE-2026-8955: Privilege escalation in the DOM: Workers component
 (moderate)
  - CVE-2026-8956: Integer overflow in the Networking: JAR component
 (moderate)
  - CVE-2026-8957: Privilege escalation in the Enterprise Policies
 component (moderate)
  - CVE-2026-8958: Information disclosure, sandbox escape in the Security:
 Process Sandboxing component (moderate)
  - CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in
 the Widget: Win32 component (moderate)
  - CVE-2026-8961: Spoofing issue in the Form Autofill component (low)
  - CVE-2026-8962: Mitigation bypass in the DOM: Security component (low)
  - CVE-2026-8968: Denial-of-service due to invalid pointer in the
 Audio/Video: Web Codecs component(low)
  - CVE-2026-8970: Privilege escalation in the Security component (low)
  - CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and
 Firefox 151 (moderate)
  - CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox
 ESR 140.11 and Firefox 151 (hight)

 https://www.mozilla.org/en-US/security/advisories/mfsa2026-48/
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23111#comment:14>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.