Re: [BLFS Trac] #23763: firefox-153.1.0esr

BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23763: firefox-153.1.0esr
-------------------------+-------------------------------
 Reporter:  Joe Locash   |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  elevated     |   Milestone:  98-Security
Component:  BOOK         |     Version:  git
 Severity:  high         |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Changes (by Joe Locash):

 * milestone:  13.1 => 98-Security
 * owner:  Joe Locash => SecurityAdvisory
 * priority:  normal => elevated
 * severity:  normal => high
 * status:  assigned => new

Comment:

 Security fixes:
  - CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL
 component (high)
  - CVE-2026-74935: Privilege escalation in the DOM: Networking component
 (high)
  - CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
 (high)
  - CVE-2026-74937: Use-after-free in the JavaScript: GC component (high)
  - CVE-2026-74938: Mitigation bypass in the JavaScript: GC component
 (high)
  - CVE-2026-74939: Privilege escalation in the DOM: Navigation component
 (high)
  - CVE-2026-74940: Use-after-free in the Graphics: Text component (high)
  - CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL
 component (high)
  - CVE-2026-74942: Privilege escalation in the Remote Settings Client
 component (high)
  - CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
 (high)
  - CVE-2026-74944: Use-after-free in the DOM: Core & HTML component (high)
  - CVE-2026-74945: Information disclosure in the Graphics: Text component
 (high)
  - CVE-2026-74946: Privilege escalation due to incorrect boundary
 conditions in the Graphics: CanvasWebGL component (high)
  - CVE-2026-74947: Privilege escalation due to invalid pointer in the
 Graphics component (high)
  - CVE-2026-74948: Information disclosure in the Graphics component (high)
  - CVE-2026-74949: Privilege escalation due to use-after-free in the
 Graphics: Canvas2D component (high)
  - CVE-2026-74950: Privilege escalation in the Downloads API component
 (moderate)
  - CVE-2026-74953: Privilege escalation in the Networking: Cookies
 component (moderate)
  - CVE-2026-74954: Information disclosure due to side-channel in the
 Storage: Cache API component (moderate)
  - CVE-2026-74955: Privilege escalation in the Request Handling component
 (moderate)
  - CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers
 component (moderate)
  - CVE-2026-74957: Mitigation bypass in the Safe Browsing component
 (moderate)
  - CVE-2026-74958: Information disclosure in the WebRTC component
 (moderate)
  - CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
 (moderate)
  - CVE-2026-74960: Site isolation issue in the WebExtensions component
 (moderate)
  - CVE-2026-74961: Side-channel in the Web Audio component (moderate)
  - CVE-2026-74962: Site isolation issue in the Networking: Cookies
 component (moderate)
  - CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies
 component (moderate)
  - CVE-2026-74964: Integer overflow in the Graphics component (moderate)
  - CVE-2026-74965: Privilege escalation in the Shell Integration component
 (moderate)
  - CVE-2026-74966: Information disclosure in the Form Autofill component
 (moderate)
  - CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback
 component (moderate)
  - CVE-2026-74968: Site isolation issue in the Graphics: WebRender
 component (moderate)
  - CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
 (moderate)
  - CVE-2026-74970: Site isolation issue in the Graphics component
 (moderate)
  - CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus
 Handling component (moderate)
  - CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions
 component (moderate)
  - CVE-2026-74973: Race condition, use-after-free in the Graphics
 component (moderate)
  - CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib
 component (moderate)
  - CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT
 component (low)
  - CVE-2026-74977: Integer overflow in the Graphics component (low)
  - CVE-2026-74978: Clickjacking issue in the Widget component (low)
  - CVE-2026-74979: Mitigation bypass in the Add-ons Manager component
 (low)
  - CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs
 component (low)
  - CVE-2026-74982: Denial-of-service in the Widget component (low)
  - CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
 (low)
  - CVE-2026-74984: Race condition in the JavaScript Engine component (low)
  - CVE-2026-74985: Privilege escalation in the Enterprise Policies
 component (low)
  - CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation
 component (low)
  - CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and
 Firefox 154 (high)
  - CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39,
 Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (high)

 https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23763#comment:2>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.