MGASA-2026-0441

Source
https://advisories.mageia.org/MGASA-2026-0441.html
Import Source
https://advisories.mageia.org/MGASA-2026-0441.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0441
Upstream
CVE (59)
  • CVE-2026-92005
  • CVE-2026-92006
  • CVE-2026-92007
  • CVE-2026-92008
  • CVE-2026-92009
  • CVE-2026-92010
  • CVE-2026-92011
  • CVE-2026-92012
  • CVE-2026-92013
  • CVE-2026-92014
  • CVE-2026-92015
  • CVE-2026-92016
  • CVE-2026-92017
  • CVE-2026-92018
  • CVE-2026-92019
  • CVE-2026-92020
  • CVE-2026-92021
  • CVE-2026-92022
  • CVE-2026-92023
  • CVE-2026-92024
  • CVE-2026-92025
  • CVE-2026-92026
  • CVE-2026-92027
  • CVE-2026-92028
  • CVE-2026-92029
  • CVE-2026-92030
  • CVE-2026-92031
  • CVE-2026-92032
  • CVE-2026-92038
  • CVE-2026-92039
  • CVE-2026-92041
  • CVE-2026-92042
  • CVE-2026-92043
  • CVE-2026-92044
  • CVE-2026-92045
  • CVE-2026-92046
  • CVE-2026-92047
  • CVE-2026-92052
  • CVE-2026-92053
  • CVE-2026-92054
  • CVE-2026-92055
  • CVE-2026-92056
  • CVE-2026-92057
  • CVE-2026-92058
  • CVE-2026-92059
  • CVE-2026-92060
  • CVE-2026-92062
  • CVE-2026-92064
  • CVE-2026-92067
  • CVE-2026-92068
  • CVE-2026-92069
  • CVE-2026-92070
  • CVE-2026-92072
  • CVE-2026-92073
  • CVE-2026-92074
  • CVE-2026-92075
  • CVE-2026-92076
  • CVE-2026-92077
  • CVE-2026-92078
Published
2026-09-23T16:56:55Z
Modified
2026-09-23T17:00:04Z
Summary
Updated nss & firefox packages fix security vulnerabilities
Details

Use-after-free in the Audio/Video: Web Codecs component. (CVE-2026-92005) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92006) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92007) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92008) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92009) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92010) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92011) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92012) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92013) Privilege escalation due to incorrect boundary conditions in the Graphics component. (CVE-2026-92014) Privilege escalation in the WebExtensions component. (CVE-2026-92015) Use-after-free in the Disability Access APIs component. (CVE-2026-92016) Privilege escalation in the DOM: Service Workers component. (CVE-2026-92017) Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92019) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. (CVE-2026-92020) Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021) Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022) Use-after-free in the XML component. (CVE-2026-92023) Use-after-free in the SVG component. (CVE-2026-92024) Use-after-free in the DOM: Navigation component. (CVE-2026-92025) Use-after-free in the Networking component. (CVE-2026-92026) Use-after-free in the DOM: Streams component. (CVE-2026-92027) Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028) Use-after-free in the SVG component. (CVE-2026-92029) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-92030) Information disclosure in the Graphics: ImageLib component. (CVE-2026-92031) Sandbox escape due to invalid pointer in the Graphics component. (CVE-2026-92032) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92038) Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039) Mitigation bypass in the DOM: Networking component. (CVE-2026-92041) Race condition in the DOM: Content Processes component. (CVE-2026-92042) Privilege escalation due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-92043) Information disclosure in the Networking: HTTP component. (CVE-2026-92044) Sandbox escape due to incorrect boundary conditions in the WebRTC component. (CVE-2026-92045) Use-after-free in the Graphics component. (CVE-2026-92046) Privilege escalation in the Crash Reporting component. (CVE-2026-92047) Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. (CVE-2026-92052) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-92053) Privilege escalation in the Memory component. (CVE-2026-92054) Privilege escalation in the DevTools component. (CVE-2026-92055) Use-after-free in the Graphics: Text component. (CVE-2026-92056) Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057) Use-after-free in the Graphics component. (CVE-2026-92058) Incorrect boundary conditions in the DOM: Editor component. (CVE-2026-92059) Use-after-free in the Internationalization component. (CVE-2026-92060) Privilege escalation in the Session Restore component. (CVE-2026-92062) Use-after-free in the Widget: Gtk component. (CVE-2026-92067) Site isolation issue in the Reader Mode component. (CVE-2026-92068) Spoofing issue in the DOM: Navigation component. (CVE-2026-92069) Information disclosure in the Networking component. (CVE-2026-92070) Incorrect boundary conditions in the Safe Browsing component. (CVE-2026-92072) Privilege escalation in the Enterprise Policies component. (CVE-2026-92073) Mitigation bypass in the Popup Blocker component. (CVE-2026-92074) Mitigation bypass in the Networking component. (CVE-2026-92075) Incorrect boundary conditions in the Networking component. (CVE-2026-92076) Denial-of-service in the SVG component. (CVE-2026-92077) Denial-of-service in the Security component. (CVE-2026-92078)

References
Credits

Affected packages

Mageia:10
firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-1.mga10

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0441.json"
nss

Package

Name
nss
Purl
pkg:rpm/mageia/nss?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.129.0-1.mga10

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0441.json"
firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-1.mga10

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0441.json"
Mageia:9
firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
140.16.0-1.mga9

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0441.json"
nss

Package

Name
nss
Purl
pkg:rpm/mageia/nss?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.129.0-1.mga9

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0441.json"
firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
140.16.0-1.mga9

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0441.json"