SUSE-SU-2026:4264-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264264-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4264-1
Upstream
  • CVE-2026-92005
  • CVE-2026-92006
  • CVE-2026-92007
  • CVE-2026-92008
  • CVE-2026-92009
  • CVE-2026-92010
  • CVE-2026-92011
  • CVE-2026-92012
  • CVE-2026-92013
  • CVE-2026-92015
  • CVE-2026-92016
  • CVE-2026-92017
  • CVE-2026-92018
  • CVE-2026-92019
  • CVE-2026-92020
  • CVE-2026-92022
  • CVE-2026-92023
  • CVE-2026-92024
  • CVE-2026-92025
  • CVE-2026-92026
  • CVE-2026-92027
  • CVE-2026-92028
  • CVE-2026-92029
  • CVE-2026-92030
  • CVE-2026-92031
  • CVE-2026-92032
  • CVE-2026-92035
  • CVE-2026-92038
  • CVE-2026-92039
  • CVE-2026-92041
  • CVE-2026-92042
  • CVE-2026-92043
  • CVE-2026-92044
  • CVE-2026-92045
  • CVE-2026-92046
  • CVE-2026-92047
  • CVE-2026-92048
  • CVE-2026-92049
  • CVE-2026-92052
  • CVE-2026-92053
  • CVE-2026-92054
  • CVE-2026-92055
  • CVE-2026-92056
  • CVE-2026-92057
  • CVE-2026-92058
  • CVE-2026-92059
  • CVE-2026-92060
  • CVE-2026-92062
  • CVE-2026-92064
  • CVE-2026-92065
  • CVE-2026-92067
  • CVE-2026-92068
  • CVE-2026-92069
  • CVE-2026-92070
  • CVE-2026-92071
  • CVE-2026-92072
  • CVE-2026-92073
  • CVE-2026-92074
  • CVE-2026-92075
  • CVE-2026-92076
  • CVE-2026-92077
  • CVE-2026-92078
  • CVE-2026-92079
Related
  • CVE-2026-92005
  • CVE-2026-92006
  • CVE-2026-92007
  • CVE-2026-92008
  • CVE-2026-92009
  • CVE-2026-92010
  • CVE-2026-92011
  • CVE-2026-92012
  • CVE-2026-92013
  • CVE-2026-92015
  • CVE-2026-92016
  • CVE-2026-92017
  • CVE-2026-92018
  • CVE-2026-92019
  • CVE-2026-92020
  • CVE-2026-92022
  • CVE-2026-92023
  • CVE-2026-92024
  • CVE-2026-92025
  • CVE-2026-92026
  • CVE-2026-92027
  • CVE-2026-92028
  • CVE-2026-92029
  • CVE-2026-92030
  • CVE-2026-92031
  • CVE-2026-92032
  • CVE-2026-92035
  • CVE-2026-92038
  • CVE-2026-92039
  • CVE-2026-92041
  • CVE-2026-92042
  • CVE-2026-92043
  • CVE-2026-92044
  • CVE-2026-92045
  • CVE-2026-92046
  • CVE-2026-92047
  • CVE-2026-92048
  • CVE-2026-92049
  • CVE-2026-92052
  • CVE-2026-92053
  • CVE-2026-92054
  • CVE-2026-92055
  • CVE-2026-92056
  • CVE-2026-92057
  • CVE-2026-92058
  • CVE-2026-92059
  • CVE-2026-92060
  • CVE-2026-92062
  • CVE-2026-92064
  • CVE-2026-92065
  • CVE-2026-92067
  • CVE-2026-92068
  • CVE-2026-92069
  • CVE-2026-92070
  • CVE-2026-92071
  • CVE-2026-92072
  • CVE-2026-92073
  • CVE-2026-92074
  • CVE-2026-92075
  • CVE-2026-92076
  • CVE-2026-92077
  • CVE-2026-92078
  • CVE-2026-92079
Published
2026-09-18T13:54:57Z
Modified
2026-09-19T09:00:04Z
Summary
Security update for MozillaFirefox
Details

This update for MozillaFirefox fixes the following issues:

Update to Firefox Extended Support Release 153.3.0 ESRi (MFSA 2026-93, bsc#1280371)

  • CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component.
  • CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
  • CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
  • CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
  • CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
  • CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
  • CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
  • CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
  • CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
  • CVE-2026-92015: Privilege escalation in the WebExtensions component.
  • CVE-2026-92016: Use-after-free in the Disability Access APIs component.
  • CVE-2026-92017: Privilege escalation in the DOM: Service Workers component.
  • CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component.
  • CVE-2026-92019: Mitigation bypass in the Remote Settings Client component.
  • CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component.
  • CVE-2026-92022: Use-after-free in the DOM: HTML Parser component.
  • CVE-2026-92023: Use-after-free in the XML component.
  • CVE-2026-92024: Use-after-free in the SVG component.
  • CVE-2026-92025: Use-after-free in the DOM: Navigation component.
  • CVE-2026-92026: Use-after-free in the Networking component.
  • CVE-2026-92027: Use-after-free in the DOM: Streams component.
  • CVE-2026-92028: Use-after-free in the DOM: Core & HTML component.
  • CVE-2026-92029: Use-after-free in the SVG component.
  • CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component.
  • CVE-2026-92031: Information disclosure in the Graphics: ImageLib component.
  • CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component.
  • CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component.
  • CVE-2026-92038: Mitigation bypass in the Remote Settings Client component.
  • CVE-2026-92039: Mitigation bypass in the DOM: Notifications component.
  • CVE-2026-92041: Mitigation bypass in the DOM: Networking component.
  • CVE-2026-92042: Race condition in the DOM: Content Processes component.
  • CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component.
  • CVE-2026-92044: Information disclosure in the Networking: HTTP component.
  • CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component.
  • CVE-2026-92046: Use-after-free in the Graphics component.
  • CVE-2026-92047: Privilege escalation in the Crash Reporting component.
  • CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
  • CVE-2026-92049: Use-after-free in the Widget: Win32 component.
  • CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component.
  • CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component.
  • CVE-2026-92054: Privilege escalation in the Memory component.
  • CVE-2026-92055: Privilege escalation in the DevTools component.
  • CVE-2026-92056: Use-after-free in the Graphics: Text component.
  • CVE-2026-92057: Mitigation bypass in the Enterprise Policies component.
  • CVE-2026-92058: Use-after-free in the Graphics component.
  • CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component.
  • CVE-2026-92060: Use-after-free in the Internationalization component.
  • CVE-2026-92062: Privilege escalation in the Session Restore component.
  • CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
  • CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
  • CVE-2026-92067: Use-after-free in the Widget: Gtk component.
  • CVE-2026-92068: Site isolation issue in the Reader Mode component.
  • CVE-2026-92069: Spoofing issue in the DOM: Navigation component.
  • CVE-2026-92070: Information disclosure in the Networking component.
  • CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
  • CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component.
  • CVE-2026-92073: Privilege escalation in the Enterprise Policies component.
  • CVE-2026-92074: Mitigation bypass in the Popup Blocker component.
  • CVE-2026-92075: Mitigation bypass in the Networking component.
  • CVE-2026-92076: Incorrect boundary conditions in the Networking component.
  • CVE-2026-92077: Denial-of-service in the SVG component.
  • CVE-2026-92078: Denial-of-service in the Security component.
  • CVE-2026-92079: Mitigation bypass in the Widget: Win32 component.
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise Module for Desktop Applications 15 SP7
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.3.0-150400.157.8.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaFirefox": "153.3.0-150400.157.8.1",
            "MozillaFirefox-devel": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-common": "153.3.0-150400.157.8.1",
            "MozillaFirefox-translations-other": "153.3.0-150400.157.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"