openSUSE-SU-2026:21519-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21519-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21519-1
Upstream
  • CVE-2026-12289
  • CVE-2026-12290
  • CVE-2026-12291
  • CVE-2026-12292
  • CVE-2026-12294
  • CVE-2026-12295
  • CVE-2026-12296
  • CVE-2026-12297
  • CVE-2026-12298
  • CVE-2026-12299
  • CVE-2026-12302
  • CVE-2026-12304
  • CVE-2026-12305
  • CVE-2026-12306
  • CVE-2026-12307
  • CVE-2026-12308
  • CVE-2026-12309
  • CVE-2026-12310
  • CVE-2026-12311
  • CVE-2026-12312
  • CVE-2026-12313
  • CVE-2026-12314
  • CVE-2026-12315
  • CVE-2026-12324
  • CVE-2026-12325
  • CVE-2026-12327
  • CVE-2026-12328
  • CVE-2026-12329
  • CVE-2026-12330
  • CVE-2026-15718
  • CVE-2026-15719
  • CVE-2026-16349
  • CVE-2026-16350
  • CVE-2026-16351
  • CVE-2026-16352
  • CVE-2026-16353
  • CVE-2026-16354
  • CVE-2026-16355
  • CVE-2026-16356
  • CVE-2026-16357
  • CVE-2026-16358
  • CVE-2026-16359
  • CVE-2026-16360
  • CVE-2026-16361
  • CVE-2026-16362
  • CVE-2026-16363
  • CVE-2026-16368
  • CVE-2026-16369
  • CVE-2026-16371
  • CVE-2026-16374
  • CVE-2026-16375
  • CVE-2026-16377
  • CVE-2026-16379
  • CVE-2026-16381
  • CVE-2026-16383
  • CVE-2026-16387
  • CVE-2026-16390
  • CVE-2026-16391
  • CVE-2026-16396
  • CVE-2026-16405
  • CVE-2026-16412
Related
  • CVE-2026-12289
  • CVE-2026-12290
  • CVE-2026-12291
  • CVE-2026-12292
  • CVE-2026-12294
  • CVE-2026-12295
  • CVE-2026-12296
  • CVE-2026-12297
  • CVE-2026-12298
  • CVE-2026-12299
  • CVE-2026-12302
  • CVE-2026-12304
  • CVE-2026-12305
  • CVE-2026-12306
  • CVE-2026-12307
  • CVE-2026-12308
  • CVE-2026-12309
  • CVE-2026-12310
  • CVE-2026-12311
  • CVE-2026-12312
  • CVE-2026-12313
  • CVE-2026-12314
  • CVE-2026-12315
  • CVE-2026-12324
  • CVE-2026-12325
  • CVE-2026-12327
  • CVE-2026-12328
  • CVE-2026-12329
  • CVE-2026-12330
  • CVE-2026-15718
  • CVE-2026-15719
  • CVE-2026-16349
  • CVE-2026-16350
  • CVE-2026-16351
  • CVE-2026-16352
  • CVE-2026-16353
  • CVE-2026-16354
  • CVE-2026-16355
  • CVE-2026-16356
  • CVE-2026-16357
  • CVE-2026-16358
  • CVE-2026-16359
  • CVE-2026-16360
  • CVE-2026-16361
  • CVE-2026-16362
  • CVE-2026-16363
  • CVE-2026-16368
  • CVE-2026-16369
  • CVE-2026-16371
  • CVE-2026-16374
  • CVE-2026-16375
  • CVE-2026-16377
  • CVE-2026-16379
  • CVE-2026-16381
  • CVE-2026-16383
  • CVE-2026-16387
  • CVE-2026-16390
  • CVE-2026-16391
  • CVE-2026-16396
  • CVE-2026-16405
  • CVE-2026-16412
Published
2026-08-03T17:09:17Z
Modified
2026-08-04T18:30:06.535416897Z
Summary
Security update for MozillaFirefox
Details

This update for MozillaFirefox fixes the following issues:

  • Update to Firefox Extended Support Release 140.13.0 ESR.
    • MFSA 2026-70 (bsc#1271649):
      • CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component
      • CVE-2026-15719: Site isolation issue in the DOM: Navigation component
      • CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component
      • CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component
      • CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
      • CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component
      • CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component
      • CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component
      • CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
      • CVE-2026-16354: Information disclosure in the Graphics: ImageLib component
      • CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component
      • CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
      • CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component
      • CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component
      • CVE-2026-16357: Incorrect boundary conditions in the Graphics component
      • CVE-2026-16371: Privilege escalation in the DOM: Navigation component
      • CVE-2026-16374: Information disclosure in the Framework component in DevTools
      • CVE-2026-16375: Site isolation issue in the Networking: HTTP component
      • CVE-2026-16377: Mitigation bypass in the PDF Viewer component
      • CVE-2026-16379: Privilege escalation in the DOM: Content Processes component
      • CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
      • CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component
      • CVE-2026-16383: Mitigation bypass in the DOM: Networking component
      • CVE-2026-16387: Site isolation issue in the Networking component
      • CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
      • CVE-2026-16391: Information disclosure in the Storage: IndexedDB component
      • CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component
      • CVE-2026-16396: Privilege escalation in WebExtensions
      • CVE-2026-16405: Information disclosure in the Networking: WebSockets component
      • CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
      • CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
      • CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13
  • Remove obsolete mozilla-nss-certs (bsc#1269226).
References

Affected packages

openSUSE:Leap 16.0 / MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
140.13.0-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox-branding-upstream": "140.13.0-160000.1.1",
            "MozillaFirefox-translations-other": "140.13.0-160000.1.1",
            "MozillaFirefox": "140.13.0-160000.1.1",
            "MozillaFirefox-translations-common": "140.13.0-160000.1.1",
            "MozillaFirefox-devel": "140.13.0-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21519-1.json"