SUSE-SU-2026:21607-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621607-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21607-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:21607-1
Upstream
CVE (4)
  • CVE-2026-8090
  • CVE-2026-8091
  • CVE-2026-8092
  • CVE-2026-8094
Related
Published
2026-05-12T10:23:16Z
Modified
2026-05-16T18:24:31Z
Summary
Security update for MozillaFirefox
Details

This update for MozillaFirefox fixes the following issues

Updated to Firefox Extended Support Release 140.10.2 ESR (bsc#1264378,MFSA 2026-41):

  • CVE-2026-8090: Use-after-free in the DOM: Networking component.
  • CVE-2026-8091: Incorrect boundary conditions in the Audio/Video: Playback component.
  • CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2.
  • CVE-2026-8094: Other issue in the WebRTC component.
References

Affected packages