Re: [BLFS Trac] #23624: firefox-153.0esr

BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]> Tue, 21 Jul 2026 18:45:29 -0000
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23624: firefox-153.0esr
-------------------------+------------------------
 Reporter:  Bruce Dubbs  |       Owner:  blfs-book
     Type:  enhancement  |      Status:  new
 Priority:  normal       |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------
Comment (by Joe Locash):

 For changes see: https://www.firefox.com/en-US/firefox/153.0/releasenotes/

 Security fixes:
  - CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation
 component (high)
  - CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb
 component (high)
  - CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
 (high)
  - CVE-2026-16351: Sandbox escape due to use-after-free in the DOM:
 Navigation component (high)
  - CVE-2026-16352: Sandbox escape due to use-after-free in the Disability
 Access APIs component (high)
  - CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly
 component (high)
  - CVE-2026-16364: Incorrect boundary conditions in the Audio/Video:
 Playback component (high)
  - CVE-2026-16365: Privilege escalation in the DOM: Workers component
 (high)
  - CVE-2026-16366: Privilege escalation in the DOM: Navigation component
 (high)
  - CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
 (high)
  - CVE-2026-16354: Information disclosure in the Graphics: ImageLib
 component (high)
  - CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability
 Access APIs component (high)
  - CVE-2026-16368: Incorrect boundary conditions in the JavaScript:
 WebAssembly component (high)
  - CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly
 component (high)
  - CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT
 component (high)
  - CVE-2026-16356: Sandbox escape due to use-after-free in the Disability
 Access APIs component (high)
  - CVE-2026-16357: Incorrect boundary conditions in the Graphics component
 (high)
  - CVE-2026-16370: Mitigation bypass in the DOM: Networking component
 (moderate)
  - CVE-2026-16371: Privilege escalation in the DOM: Navigation component
 (moderate)
  - CVE-2026-16372: Privilege escalation in the DOM: Content Processes
 component (moderate)
  - CVE-2026-16373: Information disclosure in the Privacy component in
 Firefox for Android (moderate)
  - CVE-2026-16374: Information disclosure in the Framework component in
 DevTools (moderate)
  - CVE-2026-16375: Site isolation issue in the Networking: HTTP component
 (moderate)
  - CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
 (moderate)
  - CVE-2026-16377: Mitigation bypass in the PDF Viewer component
 (moderate)
  - CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop
 component (moderate)
  - CVE-2026-16379: Privilege escalation in the DOM: Content Processes
 component (moderate)
  - CVE-2026-16358: Site isolation issue in the Graphics: WebRender
 component (moderate)
  - CVE-2026-16380: Mitigation bypass in the Networking component
 (moderate)
  - CVE-2026-16381: Same-origin policy bypass in the Networking: DNS
 component (moderate)
  - CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component
 (moderate)
  - CVE-2026-16383: Mitigation bypass in the DOM: Networking component
 (moderate)
  - CVE-2026-16384: Information disclosure due to uninitialized memory in
 the Graphics: WebGPU component (moderate)
  - CVE-2026-16385: Information disclosure due to uninitialized memory in
 the Graphics: WebGPU component (moderate)
  - CVE-2026-16386: Information disclosure due to uninitialized memory in
 the Graphics: WebGPU component (moderate)
  - CVE-2026-16387: Site isolation issue in the Networking component
 (moderate)
  - CVE-2026-16388: Sandbox escape in the DOM: Networking component
 (moderate)
  - CVE-2026-16389: Incorrect boundary conditions, integer overflow in the
 Libraries component in NSS (moderate)
  - CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
 (moderate)
  - CVE-2026-16391: Information disclosure in the Storage: IndexedDB
 component (moderate)
  - CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT
 component (moderate)
  - CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU
 component (moderate)
  - CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
 component (moderate)
  - CVE-2026-16394: Mitigation bypass in the DOM: Security component
 (moderate)
  - CVE-2026-16395: Integer overflow in the Audio/Video component
 (moderate)
  - CVE-2026-16396: Privilege escalation in WebExtensions (moderate)
  - CVE-2026-16397: Clickjacking issue in the WebExtensions component in
 Firefox for Android (moderate)
  - CVE-2026-16398: Site isolation issue in the Graphics component
 (moderate)
  - CVE-2026-16399: Site isolation issue in the DOM: Navigation component
 (moderate)
  - CVE-2026-16400: Information disclosure in the DOM: Security component
 (moderate)
  - CVE-2026-16401: Privilege escalation in the Data Loss Prevention
 component (moderate)
  - CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
 (moderate)
  - CVE-2026-16403: Spoofing issue in the Address Bar component (low)
  - CVE-2026-16404: Spoofing issue in Firefox for Android (low)
  - CVE-2026-16405: Information disclosure in the Networking: WebSockets
 component (low)
  - CVE-2026-16406: Mitigation bypass in the Networking component (low)
  - CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component
 (low)
  - CVE-2026-16408: Integer overflow in the Audio/Video: Playback component
 (low)
  - CVE-2026-16409: Invalid pointer in the Security: PSM component (low)
  - CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT
 component (low)
  - CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and
 Firefox 153 (high)
  - CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox
 ESR 140.13 and Firefox 153 (high)

 https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23624#comment:4>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page