This update for MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues:
Changes in MozillaFirefox:
This update ships Firefox Extended Support Release 153.2.0 ESR
MFSA 2026-85 (bsc#1278001):
CVE-2026-75874: Sandbox escape in the Remote Settings Client component
CVE-2026-84118: Use-after-free in the JavaScript: GC component
CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component
CVE-2026-84120: Use-after-free in the Audio/Video component
CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component
CVE-2026-84122: Use-after-free in the Audio/Video component
CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component
CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
CVE-2026-74952: Privilege escalation in the Application Update component
CVE-2026-84129: Site isolation issue in the DOM: Navigation component
CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component
CVE-2026-84132: Information disclosure in the Networking: HTTP component
CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component
CVE-2026-84134: Other issue in the Profile Backup component
CVE-2026-84136: Other issue in the DOM: Navigation component
CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
CVE-2026-84139: Clickjacking issue in the DOM: Events component
CVE-2026-84140: Site isolation issue in the DOM: Navigation component
CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
Fixed: Various security fixes.
MFSA 2026-77 (bsc#1274867)
Firefox Extended Support Release 153.0esr ESR
New: ## General
New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy.
New: ## Sidebar and Tabs
New: ## Security & Privacy
New: ## Translations
New: ## Accessibility
New: ## Windows
New: ## macOS
New: ## Linux
HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views.
Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy.
Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649)
CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component
CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component
CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component
CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component
CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component
CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component
CVE-2026-16365 Privilege escalation in the DOM: Workers component
CVE-2026-16366 Privilege escalation in the DOM: Navigation component
CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component
CVE-2026-16354 Information disclosure in the Graphics: ImageLib component
CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component
CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component
CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component
CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component
CVE-2026-16357 Incorrect boundary conditions in the Graphics component
CVE-2026-16370 Mitigation bypass in the DOM: Networking component
CVE-2026-16371 Privilege escalation in the DOM: Navigation component
CVE-2026-16372 Privilege escalation in the DOM: Content Processes component
CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android
CVE-2026-16374 Information disclosure in the Framework component in DevTools
CVE-2026-16375 Site isolation issue in the Networking: HTTP component
CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component
CVE-2026-16377 Mitigation bypass in the PDF Viewer component
CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component
CVE-2026-16379 Privilege escalation in the DOM: Content Processes component
CVE-2026-16358 Site isolation issue in the Graphics: WebRender component
CVE-2026-16380 Mitigation bypass in the Networking component
CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component
CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component
CVE-2026-16383 Mitigation bypass in the DOM: Networking component
CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
CVE-2026-16387 Site isolation issue in the Networking component
CVE-2026-16388 Sandbox escape in the DOM: Networking component
CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS
CVE-2026-16390 Mitigation bypass in the Enterprise Policies component
CVE-2026-16391 Information disclosure in the Storage: IndexedDB component
CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component
CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component
CVE-2026-16394 Mitigation bypass in the DOM: Security component
CVE-2026-16395 Integer overflow in the Audio/Video component
CVE-2026-16396 Privilege escalation in WebExtensions
CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android
CVE-2026-16398 Site isolation issue in the Graphics component
CVE-2026-16399 Site isolation issue in the DOM: Navigation component
CVE-2026-16400 Information disclosure in the DOM: Security component
CVE-2026-16401 Privilege escalation in the Data Loss Prevention component
CVE-2026-16402 Integer overflow in the Graphics: ImageLib component
CVE-2026-16403 Spoofing issue in the Address Bar component
CVE-2026-16404 Spoofing issue in Firefox for Android
CVE-2026-16405 Information disclosure in the Networking: WebSockets component
CVE-2026-16406 Mitigation bypass in the Networking component
CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component
CVE-2026-16408 Integer overflow in the Audio/Video: Playback component
CVE-2026-16409 Invalid pointer in the Security: PSM component
CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-16411 Memory safety bugs fixed in Firefox 153
CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867)
CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component
CVE-2026-74935 Privilege escalation in the DOM: Networking component
CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component
CVE-2026-74939 Privilege escalation in the DOM: Navigation component
CVE-2026-74940 Use-after-free in the Graphics: Text component
CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component
CVE-2026-74942 Privilege escalation in the Remote Settings Client component
CVE-2026-74943 Use-after-free in the Graphics: ImageLib component
CVE-2026-74944 Use-after-free in the DOM: Core & HTML component
CVE-2026-74945 Information disclosure in the Graphics: Text component
CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2026-74948 Information disclosure in the Graphics component
CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component
CVE-2026-74953 Privilege escalation in the Networking: Cookies component
CVE-2026-74957 Mitigation bypass in the Safe Browsing component
CVE-2026-74959 Mitigation bypass in the Storage: Cache API component
CVE-2026-74960 Site isolation issue in the WebExtensions component
CVE-2026-74962 Site isolation issue in the Networking: Cookies component
CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component
CVE-2026-74964 Integer overflow in the Graphics component
CVE-2026-74965 Privilege escalation in the Shell Integration component
CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component
CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component
CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component
CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component
CVE-2026-74973 Race condition, use-after-free in the Graphics component
CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component
CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component
CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen:
Update to version v0.29.4+git0:
pub access to ReprType fieldsUpdate to version 0.29.2+git0:
Update to version 0.29.2+git0:
clippy::uninlined_format_argsChanges in mozilla-nspr:
Update to NSPR 4.39:
Update to version 4.38.2:
Update to version 4.38.1:
Update to version 4.38:
Update to version 4.37:
Changes in mozilla-nss:
Fix potential crash in nss-fips-approved-crypto-non-ec.patch (boo#1279863)
Fix upper bound to allow FIPS approval for P-521.
Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698).
Don't consider unapproved algorithms for TLS 1.3 in FIPS mode.
Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262).
Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698).
Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263).
Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772).
Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773).
Add zeroization for ML-KEM, ported from upstream (bsc#1272774).
Add zeroization for ML-DSA (bsc#1272774).
Add ML-DSA robustness and test fixes.
Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262).
Apply jitter entropy patch unconditionally (bsc#1262701).
Update to NSS 3.125:
PR_Sleep yield for non-blocking sockets in ssl3_SendApplicationDatalocal declarations{
"binaries": [
{
"MozillaFirefox": "153.2.0-118.5.4",
"MozillaFirefox-branding-SLE": "153-41.3.8",
"MozillaFirefox-devel": "153.2.0-118.5.4",
"MozillaFirefox-translations-common": "153.2.0-118.5.4",
"libfreebl3": "3.125-58.147.1",
"libfreebl3-32bit": "3.125-58.147.1",
"libsoftokn3": "3.125-58.147.1",
"libsoftokn3-32bit": "3.125-58.147.1",
"mozilla-nspr": "4.39-19.39.1",
"mozilla-nspr-32bit": "4.39-19.39.1",
"mozilla-nspr-devel": "4.39-19.39.1",
"mozilla-nss": "3.125-58.147.1",
"mozilla-nss-32bit": "3.125-58.147.1",
"mozilla-nss-certs": "3.125-58.147.1",
"mozilla-nss-certs-32bit": "3.125-58.147.1",
"mozilla-nss-devel": "3.125-58.147.1",
"mozilla-nss-sysinit": "3.125-58.147.1",
"mozilla-nss-sysinit-32bit": "3.125-58.147.1",
"mozilla-nss-tools": "3.125-58.147.1"
}
]
}{
"binaries": [
{
"MozillaFirefox": "153.2.0-118.5.4",
"MozillaFirefox-branding-SLE": "153-41.3.8",
"MozillaFirefox-devel": "153.2.0-118.5.4",
"MozillaFirefox-translations-common": "153.2.0-118.5.4",
"libfreebl3": "3.125-58.147.1",
"libfreebl3-32bit": "3.125-58.147.1",
"libsoftokn3": "3.125-58.147.1",
"libsoftokn3-32bit": "3.125-58.147.1",
"mozilla-nspr": "4.39-19.39.1",
"mozilla-nspr-32bit": "4.39-19.39.1",
"mozilla-nspr-devel": "4.39-19.39.1",
"mozilla-nss": "3.125-58.147.1",
"mozilla-nss-32bit": "3.125-58.147.1",
"mozilla-nss-certs": "3.125-58.147.1",
"mozilla-nss-certs-32bit": "3.125-58.147.1",
"mozilla-nss-devel": "3.125-58.147.1",
"mozilla-nss-sysinit": "3.125-58.147.1",
"mozilla-nss-sysinit-32bit": "3.125-58.147.1",
"mozilla-nss-tools": "3.125-58.147.1"
}
]
}{
"binaries": [
{
"MozillaFirefox": "153.2.0-118.5.4",
"MozillaFirefox-branding-SLE": "153-41.3.8",
"MozillaFirefox-devel": "153.2.0-118.5.4",
"MozillaFirefox-translations-common": "153.2.0-118.5.4",
"libfreebl3": "3.125-58.147.1",
"libfreebl3-32bit": "3.125-58.147.1",
"libsoftokn3": "3.125-58.147.1",
"libsoftokn3-32bit": "3.125-58.147.1",
"mozilla-nspr": "4.39-19.39.1",
"mozilla-nspr-32bit": "4.39-19.39.1",
"mozilla-nspr-devel": "4.39-19.39.1",
"mozilla-nss": "3.125-58.147.1",
"mozilla-nss-32bit": "3.125-58.147.1",
"mozilla-nss-certs": "3.125-58.147.1",
"mozilla-nss-certs-32bit": "3.125-58.147.1",
"mozilla-nss-devel": "3.125-58.147.1",
"mozilla-nss-sysinit": "3.125-58.147.1",
"mozilla-nss-sysinit-32bit": "3.125-58.147.1",
"mozilla-nss-tools": "3.125-58.147.1"
}
]
}{
"binaries": [
{
"MozillaFirefox": "153.2.0-118.5.4",
"MozillaFirefox-branding-SLE": "153-41.3.8",
"MozillaFirefox-devel": "153.2.0-118.5.4",
"MozillaFirefox-translations-common": "153.2.0-118.5.4",
"libfreebl3": "3.125-58.147.1",
"libfreebl3-32bit": "3.125-58.147.1",
"libsoftokn3": "3.125-58.147.1",
"libsoftokn3-32bit": "3.125-58.147.1",
"mozilla-nspr": "4.39-19.39.1",
"mozilla-nspr-32bit": "4.39-19.39.1",
"mozilla-nspr-devel": "4.39-19.39.1",
"mozilla-nss": "3.125-58.147.1",
"mozilla-nss-32bit": "3.125-58.147.1",
"mozilla-nss-certs": "3.125-58.147.1",
"mozilla-nss-certs-32bit": "3.125-58.147.1",
"mozilla-nss-devel": "3.125-58.147.1",
"mozilla-nss-sysinit": "3.125-58.147.1",
"mozilla-nss-sysinit-32bit": "3.125-58.147.1",
"mozilla-nss-tools": "3.125-58.147.1"
}
]
}{
"binaries": [
{
"MozillaFirefox": "153.2.0-118.5.4",
"MozillaFirefox-branding-SLE": "153-41.3.8",
"MozillaFirefox-devel": "153.2.0-118.5.4",
"MozillaFirefox-translations-common": "153.2.0-118.5.4",
"libfreebl3": "3.125-58.147.1",
"libfreebl3-32bit": "3.125-58.147.1",
"libsoftokn3": "3.125-58.147.1",
"libsoftokn3-32bit": "3.125-58.147.1",
"mozilla-nspr": "4.39-19.39.1",
"mozilla-nspr-32bit": "4.39-19.39.1",
"mozilla-nspr-devel": "4.39-19.39.1",
"mozilla-nss": "3.125-58.147.1",
"mozilla-nss-32bit": "3.125-58.147.1",
"mozilla-nss-certs": "3.125-58.147.1",
"mozilla-nss-certs-32bit": "3.125-58.147.1",
"mozilla-nss-devel": "3.125-58.147.1",
"mozilla-nss-sysinit": "3.125-58.147.1",
"mozilla-nss-sysinit-32bit": "3.125-58.147.1",
"mozilla-nss-tools": "3.125-58.147.1"
}
]
}{
"binaries": [
{
"MozillaFirefox": "153.2.0-118.5.4",
"MozillaFirefox-branding-SLE": "153-41.3.8",
"MozillaFirefox-devel": "153.2.0-118.5.4",
"MozillaFirefox-translations-common": "153.2.0-118.5.4",
"libfreebl3": "3.125-58.147.1",
"libfreebl3-32bit": "3.125-58.147.1",
"libsoftokn3": "3.125-58.147.1",
"libsoftokn3-32bit": "3.125-58.147.1",
"mozilla-nspr": "4.39-19.39.1",
"mozilla-nspr-32bit": "4.39-19.39.1",
"mozilla-nspr-devel": "4.39-19.39.1",
"mozilla-nss": "3.125-58.147.1",
"mozilla-nss-32bit": "3.125-58.147.1",
"mozilla-nss-certs": "3.125-58.147.1",
"mozilla-nss-certs-32bit": "3.125-58.147.1",
"mozilla-nss-devel": "3.125-58.147.1",
"mozilla-nss-sysinit": "3.125-58.147.1",
"mozilla-nss-sysinit-32bit": "3.125-58.147.1",
"mozilla-nss-tools": "3.125-58.147.1"
}
]
}{
"binaries": [
{
"MozillaFirefox": "153.2.0-118.5.4",
"MozillaFirefox-branding-SLE": "153-41.3.8",
"MozillaFirefox-devel": "153.2.0-118.5.4",
"MozillaFirefox-translations-common": "153.2.0-118.5.4",
"libfreebl3": "3.125-58.147.1",
"libfreebl3-32bit": "3.125-58.147.1",
"libsoftokn3": "3.125-58.147.1",
"libsoftokn3-32bit": "3.125-58.147.1",
"mozilla-nspr": "4.39-19.39.1",
"mozilla-nspr-32bit": "4.39-19.39.1",
"mozilla-nspr-devel": "4.39-19.39.1",
"mozilla-nss": "3.125-58.147.1",
"mozilla-nss-32bit": "3.125-58.147.1",
"mozilla-nss-certs": "3.125-58.147.1",
"mozilla-nss-certs-32bit": "3.125-58.147.1",
"mozilla-nss-devel": "3.125-58.147.1",
"mozilla-nss-sysinit": "3.125-58.147.1",
"mozilla-nss-sysinit-32bit": "3.125-58.147.1",
"mozilla-nss-tools": "3.125-58.147.1"
}
]
}{
"binaries": [
{
"MozillaFirefox": "153.2.0-118.5.4",
"MozillaFirefox-branding-SLE": "153-41.3.8",
"MozillaFirefox-devel": "153.2.0-118.5.4",
"MozillaFirefox-translations-common": "153.2.0-118.5.4",
"libfreebl3": "3.125-58.147.1",
"libfreebl3-32bit": "3.125-58.147.1",
"libsoftokn3": "3.125-58.147.1",
"libsoftokn3-32bit": "3.125-58.147.1",
"mozilla-nspr": "4.39-19.39.1",
"mozilla-nspr-32bit": "4.39-19.39.1",
"mozilla-nspr-devel": "4.39-19.39.1",
"mozilla-nss": "3.125-58.147.1",
"mozilla-nss-32bit": "3.125-58.147.1",
"mozilla-nss-certs": "3.125-58.147.1",
"mozilla-nss-certs-32bit": "3.125-58.147.1",
"mozilla-nss-devel": "3.125-58.147.1",
"mozilla-nss-sysinit": "3.125-58.147.1",
"mozilla-nss-sysinit-32bit": "3.125-58.147.1",
"mozilla-nss-tools": "3.125-58.147.1"
}
]
}