[BLFS Trac] #23453: firefox-140.12.0esr and js-140.12.0 (spidermonkey)
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23453: firefox-140.12.0esr and js-140.12.0 (spidermonkey)
-------------------------+-----------------------
Reporter: Joe Locash | Owner: blfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Keywords:
-------------------------+-----------------------
Security fixes for 140.12.0esr:
- CVE-2026-12289: Privilege escalation in the Graphics: WebRender
component (high)
- CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12 (high)
- CVE-2026-12291: Use-after-free in the Networking: HTTP component (high)
- CVE-2026-12292: Incorrect boundary conditions in the Web Audio
component (high)
- CVE-2026-12294: Sandbox escape in the DOM: Workers component (high)
- CVE-2026-12295: Sandbox escape in the DOM: Navigation component (high)
- CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12 (high)
- CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing
component (high)
- CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in
the Networking component (high)
- CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component
(high)
- CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12 (high)
- CVE-2026-12302: Mitigation bypass in the DOM: Security component
(moderate)
- CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies
component (moderate)
- CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12
(moderate)
- CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12
(moderate)
- CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12
(moderate)
- CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12
(moderate)
- CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12
(moderate)
- CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12
(moderate)
- CVE-2026-12311: Information disclosure, sandbox escape in the Security:
Process Sandboxing component (moderate)
- CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12
(moderate)
- CVE-2026-12313: Information disclosure, sandbox escape in the Security:
Process Sandboxing component (moderate)
- CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12
(moderate)
- CVE-2026-12315: Mitigation bypass in the DOM: Security component
(moderate)
- CVE-2026-12330: Incorrect boundary conditions in the
Internationalization component (moderate)
- CVE-2026-12324: Incorrect boundary conditions in the Graphics:
CanvasWebGL component (low)
- CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component
(low)
- CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12,
Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (moderate)
- CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox
ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (high)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23453>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page