openSUSE-SU-2026:21594-1: moderate: Security update for MozillaFirefox
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for mozillafirefox
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21594-1
Rating: moderate
References:
* bsc#1274867
Cross-References:
* CVE-2026-74934
* CVE-2026-74935
* CVE-2026-74936
* CVE-2026-74939
* CVE-2026-74940
* CVE-2026-74941
* CVE-2026-74942
* CVE-2026-74943
* CVE-2026-74944
* CVE-2026-74945
* CVE-2026-74946
* CVE-2026-74948
* CVE-2026-74949
* CVE-2026-74953
* CVE-2026-74957
* CVE-2026-74959
* CVE-2026-74960
* CVE-2026-74962
* CVE-2026-74963
* CVE-2026-74964
* CVE-2026-74965
* CVE-2026-74967
* CVE-2026-74969
* CVE-2026-74971
* CVE-2026-74972
* CVE-2026-74973
* CVE-2026-74974
* CVE-2026-74976
* CVE-2026-74983
* CVE-2026-74987
* CVE-2026-74990
CVSS scores:
* CVE-2026-74934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74935 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74936 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-74963 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-74990 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 31 vulnerabilities and has one bug fix can now be installed.
Description:
This update for MozillaFirefox fixes the following issues:
Update to Firefox Extended Support Release 140.14.0 ESR.
- MFSA 2026-76 (bsc#1274867)
* CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
* CVE-2026-74935: Privilege escalation in the DOM: Networking component
* CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
* CVE-2026-74939: Privilege escalation in the DOM: Navigation component
* CVE-2026-74940: Use-after-free in the Graphics: Text component
* CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component
* CVE-2026-74942: Privilege escalation in the Remote Settings Client component
* CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
* CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
* CVE-2026-74945: Information disclosure in the Graphics: Text component
* CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
* CVE-2026-74948: Information disclosure in the Graphics component
* CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics:Canvas2D component
* CVE-2026-74953: Privilege escalation in the Networking: Cookies component
* CVE-2026-74957: Mitigation bypass in the Safe Browsing component
* CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
* CVE-2026-74960: Site isolation issue in the WebExtensions component
* CVE-2026-74962: Site isolation issue in the Networking: Cookies component
* CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component
* CVE-2026-74964: Integer overflow in the Graphics component
* CVE-2026-74965: Privilege escalation in the Shell Integration component
* CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component
* CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
* CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component
* CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component
* CVE-2026-74973: Race condition, use-after-free in the Graphics component
* CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
* CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
* CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
* CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and
Firefox 154
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1464=1
Package List:
- openSUSE Leap 16.0:
MozillaFirefox-140.14.0-160000.1.1
MozillaFirefox-branding-upstream-140.14.0-160000.1.1
MozillaFirefox-devel-140.14.0-160000.1.1
MozillaFirefox-translations-common-140.14.0-160000.1.1
MozillaFirefox-translations-other-140.14.0-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-74934.html
* https://www.suse.com/security/cve/CVE-2026-74935.html
* https://www.suse.com/security/cve/CVE-2026-74936.html
* https://www.suse.com/security/cve/CVE-2026-74939.html
* https://www.suse.com/security/cve/CVE-2026-74940.html
* https://www.suse.com/security/cve/CVE-2026-74941.html
* https://www.suse.com/security/cve/CVE-2026-74942.html
* https://www.suse.com/security/cve/CVE-2026-74943.html
* https://www.suse.com/security/cve/CVE-2026-74944.html
* https://www.suse.com/security/cve/CVE-2026-74945.html
* https://www.suse.com/security/cve/CVE-2026-74946.html
* https://www.suse.com/security/cve/CVE-2026-74948.html
* https://www.suse.com/security/cve/CVE-2026-74949.html
* https://www.suse.com/security/cve/CVE-2026-74953.html
* https://www.suse.com/security/cve/CVE-2026-74957.html
* https://www.suse.com/security/cve/CVE-2026-74959.html
* https://www.suse.com/security/cve/CVE-2026-74960.html
* https://www.suse.com/security/cve/CVE-2026-74962.html
* https://www.suse.com/security/cve/CVE-2026-74963.html
* https://www.suse.com/security/cve/CVE-2026-74964.html
* https://www.suse.com/security/cve/CVE-2026-74965.html
* https://www.suse.com/security/cve/CVE-2026-74967.html
* https://www.suse.com/security/cve/CVE-2026-74969.html
* https://www.suse.com/security/cve/CVE-2026-74971.html
* https://www.suse.com/security/cve/CVE-2026-74972.html
* https://www.suse.com/security/cve/CVE-2026-74973.html
* https://www.suse.com/security/cve/CVE-2026-74974.html
* https://www.suse.com/security/cve/CVE-2026-74976.html
* https://www.suse.com/security/cve/CVE-2026-74983.html
* https://www.suse.com/security/cve/CVE-2026-74987.html
* https://www.suse.com/security/cve/CVE-2026-74990.html