openSUSE-SU-2026:21594-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21594-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21594-1
Upstream
CVE (31)
  • CVE-2026-74934
  • CVE-2026-74935
  • CVE-2026-74936
  • CVE-2026-74939
  • CVE-2026-74940
  • CVE-2026-74941
  • CVE-2026-74942
  • CVE-2026-74943
  • CVE-2026-74944
  • CVE-2026-74945
  • CVE-2026-74946
  • CVE-2026-74948
  • CVE-2026-74949
  • CVE-2026-74953
  • CVE-2026-74957
  • CVE-2026-74959
  • CVE-2026-74960
  • CVE-2026-74962
  • CVE-2026-74963
  • CVE-2026-74964
  • CVE-2026-74965
  • CVE-2026-74967
  • CVE-2026-74969
  • CVE-2026-74971
  • CVE-2026-74972
  • CVE-2026-74973
  • CVE-2026-74974
  • CVE-2026-74976
  • CVE-2026-74983
  • CVE-2026-74987
  • CVE-2026-74990
Related
Published
2026-08-19T13:10:07Z
Modified
2026-08-21T09:15:07Z
Summary
Security update for MozillaFirefox
Details

This update for MozillaFirefox fixes the following issues:

Update to Firefox Extended Support Release 140.14.0 ESR.

  • MFSA 2026-76 (bsc#1274867)
    • CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
    • CVE-2026-74935: Privilege escalation in the DOM: Networking component
    • CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
    • CVE-2026-74939: Privilege escalation in the DOM: Navigation component
    • CVE-2026-74940: Use-after-free in the Graphics: Text component
    • CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component
    • CVE-2026-74942: Privilege escalation in the Remote Settings Client component
    • CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
    • CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
    • CVE-2026-74945: Information disclosure in the Graphics: Text component
    • CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    • CVE-2026-74948: Information disclosure in the Graphics component
    • CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics:Canvas2D component
    • CVE-2026-74953: Privilege escalation in the Networking: Cookies component
    • CVE-2026-74957: Mitigation bypass in the Safe Browsing component
    • CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
    • CVE-2026-74960: Site isolation issue in the WebExtensions component
    • CVE-2026-74962: Site isolation issue in the Networking: Cookies component
    • CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component
    • CVE-2026-74964: Integer overflow in the Graphics component
    • CVE-2026-74965: Privilege escalation in the Shell Integration component
    • CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component
    • CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
    • CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component
    • CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component
    • CVE-2026-74973: Race condition, use-after-free in the Graphics component
    • CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
    • CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
    • CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
    • CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
    • CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
References

Affected packages

openSUSE:Leap 16.0 / MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
140.14.0-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "MozillaFirefox":  "140.14.0-160000.1.1",
            "MozillaFirefox-branding-upstream":  "140.14.0-160000.1.1",
            "MozillaFirefox-devel":  "140.14.0-160000.1.1",
            "MozillaFirefox-translations-common":  "140.14.0-160000.1.1",
            "MozillaFirefox-translations-other":  "140.14.0-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21594-1.json"