SUSE-SU-2026:3683-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263683-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3683-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3683-1
Upstream
CVE (58)
  • CVE-2026-74934
  • CVE-2026-74935
  • CVE-2026-74936
  • CVE-2026-74937
  • CVE-2026-74938
  • CVE-2026-74939
  • CVE-2026-74940
  • CVE-2026-74941
  • CVE-2026-74942
  • CVE-2026-74943
  • CVE-2026-74944
  • CVE-2026-74945
  • CVE-2026-74946
  • CVE-2026-74947
  • CVE-2026-74948
  • CVE-2026-74949
  • CVE-2026-74950
  • CVE-2026-74951
  • CVE-2026-74952
  • CVE-2026-74953
  • CVE-2026-74954
  • CVE-2026-74955
  • CVE-2026-74956
  • CVE-2026-74957
  • CVE-2026-74958
  • CVE-2026-74959
  • CVE-2026-74960
  • CVE-2026-74961
  • CVE-2026-74962
  • CVE-2026-74963
  • CVE-2026-74964
  • CVE-2026-74965
  • CVE-2026-74966
  • CVE-2026-74967
  • CVE-2026-74968
  • CVE-2026-74969
  • CVE-2026-74970
  • CVE-2026-74971
  • CVE-2026-74972
  • CVE-2026-74973
  • CVE-2026-74974
  • CVE-2026-74975
  • CVE-2026-74976
  • CVE-2026-74977
  • CVE-2026-74978
  • CVE-2026-74979
  • CVE-2026-74980
  • CVE-2026-74981
  • CVE-2026-74982
  • CVE-2026-74983
  • CVE-2026-74984
  • CVE-2026-74985
  • CVE-2026-74986
  • CVE-2026-74987
  • CVE-2026-74988
  • CVE-2026-74989
  • CVE-2026-74990
  • CVE-2026-75874
Related
Published
2026-08-21T18:21:16Z
Modified
2026-08-26T18:23:32Z
Summary
Security update for MozillaFirefox
Details

This update for MozillaFirefox fixes the following issues:

Update to Firefox Extended Support Release 140.14.0 ESR.

  • MFSA 2026-74 (bsc#1274867):
    • CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component.
    • CVE-2026-74935: Privilege escalation in the DOM: Networking component.
    • CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component.
    • CVE-2026-74937: Use-after-free in the JavaScript: GC component.
    • CVE-2026-74938: Mitigation bypass in the JavaScript: GC component.
    • CVE-2026-74939: Privilege escalation in the DOM: Navigation component.
    • CVE-2026-74940: Use-after-free in the Graphics: Text component.
    • CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component.
    • CVE-2026-74942: Privilege escalation in the Remote Settings Client component.
    • CVE-2026-74943: Use-after-free in the Graphics: ImageLib component.
    • CVE-2026-74944: Use-after-free in the DOM: Core & HTML component.
    • CVE-2026-74945: Information disclosure in the Graphics: Text component.
    • CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
    • CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component.
    • CVE-2026-74948: Information disclosure in the Graphics component.
    • CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component.
    • CVE-2026-74950: Privilege escalation in the Downloads API component.
    • CVE-2026-74951: Clickjacking issue in Firefox for Android.
    • CVE-2026-74952: Privilege escalation in the Application Update component.
    • CVE-2026-74953: Privilege escalation in the Networking: Cookies component.
    • CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component.
    • CVE-2026-74955: Privilege escalation in the Request Handling component.
    • CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component.
    • CVE-2026-74957: Mitigation bypass in the Safe Browsing component.
    • CVE-2026-74958: Information disclosure in the WebRTC component.
    • CVE-2026-74959: Mitigation bypass in the Storage: Cache API component.
    • CVE-2026-74960: Site isolation issue in the WebExtensions component.
    • CVE-2026-74961: Side-channel in the Web Audio component.
    • CVE-2026-74962: Site isolation issue in the Networking: Cookies component.
    • CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component.
    • CVE-2026-74964: Integer overflow in the Graphics component.
    • CVE-2026-74965: Privilege escalation in the Shell Integration component.
    • CVE-2026-74966: Information disclosure in the Form Autofill component.
    • CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component.
    • CVE-2026-74968: Site isolation issue in the Graphics: WebRender component.
    • CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component.
    • CVE-2026-74970: Site isolation issue in the Graphics component.
    • CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component.
    • CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component.
    • CVE-2026-74973: Race condition, use-after-free in the Graphics component.
    • CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component.
    • CVE-2026-74975: Spoofing issue in the Downloads component in Firefox for Android.
    • CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component.
    • CVE-2026-74977: Integer overflow in the Graphics component.
    • CVE-2026-74978: Clickjacking issue in the Widget component.
    • CVE-2026-74979: Mitigation bypass in the Add-ons Manager component.
    • CVE-2026-74980: Clickjacking issue in the Downloads component in Firefox for Android.
    • CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component.
    • CVE-2026-74982: Denial-of-service in the Widget component.
    • CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component.
    • CVE-2026-74984: Race condition in the JavaScript Engine component.
    • CVE-2026-74985: Privilege escalation in the Enterprise Policies component.
    • CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component.
    • CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154.
    • CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154.
    • CVE-2026-74989: Internally found bugs fixed in Firefox 154.
    • CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154.
    • CVE-2026-75874: Sandbox escape in the Remote Settings Client component.
References

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS / MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
140.14.0-112.327.1

Ecosystem specific

{
    "binaries":  [
        {
            "MozillaFirefox":  "140.14.0-112.327.1",
            "MozillaFirefox-devel":  "140.14.0-112.327.1",
            "MozillaFirefox-translations-common":  "140.14.0-112.327.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3683-1.json"

SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 / MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
140.14.0-112.327.1

Ecosystem specific

{
    "binaries":  [
        {
            "MozillaFirefox":  "140.14.0-112.327.1",
            "MozillaFirefox-devel":  "140.14.0-112.327.1",
            "MozillaFirefox-translations-common":  "140.14.0-112.327.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3683-1.json"