SUSE-SU-2026:1830-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261830-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1830-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:1830-1
Upstream
CVE (8)
  • CVE-2026-7320
  • CVE-2026-7321
  • CVE-2026-7322
  • CVE-2026-7323
  • CVE-2026-8090
  • CVE-2026-8091
  • CVE-2026-8092
  • CVE-2026-8094
Related
Published
2026-05-12T12:00:47Z
Modified
2026-05-14T08:15:41Z
Summary
Security update for MozillaFirefox
Details

This update for MozillaFirefox fixes the following issues

Updated to Firefox Extended Support Release 140.10.2 ESR (bsc#1264378,MFSA 2026-41):

  • CVE-2026-8090: Use-after-free in the DOM: Networking component.
  • CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2.
  • CVE-2026-8094: Other issue in the WebRTC component.

Updated to Firefox Extended Support Release 140.10.1 ESR (bsc#1263110,MFSA 2026-36):

  • CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component.
  • CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component.
  • CVE-2026-7322: Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1.
  • CVE-2026-7323: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1.
  • CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component.
References

Affected packages