openSUSE-SU-2026:0315-1: moderate: Security update for mozjs102

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for mozjs102
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0315-1
Rating:             moderate
References:         #1259713 #1259728 #1259731 
Cross-References:   CVE-2026-32776 CVE-2026-32777 CVE-2026-32778
                   
CVSS scores:
                    CVE-2026-32776 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
                    CVE-2026-32777 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
                    CVE-2026-32778 (SUSE): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes three vulnerabilities is now available.

Description:

   This update for mozjs102 fixes the following issues:

   - CVE-2026-32776: NULL pointer dereference when processing empty external
     parameter entities inside an entity declaration value (boo#1259728)
   - CVE-2026-32777: NULL pointer dereference in `setContext` on retry after
     an out-of-memory condition (boo#1259713)
   - CVE-2026-32778: Denial of service due to infinite loop in DTD content
     parsing (boo#1259731)


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-315=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i686 ppc64le x86_64):

      libmozjs-102-0-102.15.1-bp157.3.3.1
      mozjs102-102.15.1-bp157.3.3.1
      mozjs102-devel-102.15.1-bp157.3.3.1


References:

   https://www.suse.com/security/cve/CVE-2026-32776.html
   https://www.suse.com/security/cve/CVE-2026-32777.html
   https://www.suse.com/security/cve/CVE-2026-32778.html
   https://bugzilla.suse.com/1259713
   https://bugzilla.suse.com/1259728
   https://bugzilla.suse.com/1259731
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.