openSUSE-SU-2026:21853-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21853-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21853-1
Upstream
CVE (24)
  • CVE-2026-74952
  • CVE-2026-75874
  • CVE-2026-84118
  • CVE-2026-84119
  • CVE-2026-84120
  • CVE-2026-84121
  • CVE-2026-84122
  • CVE-2026-84123
  • CVE-2026-84124
  • CVE-2026-84125
  • CVE-2026-84129
  • CVE-2026-84130
  • CVE-2026-84131
  • CVE-2026-84132
  • CVE-2026-84133
  • CVE-2026-84134
  • CVE-2026-84136
  • CVE-2026-84137
  • CVE-2026-84139
  • CVE-2026-84140
  • CVE-2026-84141
  • CVE-2026-84143
  • CVE-2026-84144
  • CVE-2026-84145
Related
Published
2026-09-15T14:40:48Z
Modified
2026-09-17T18:23:13Z
Summary
Security update for MozillaFirefox
Details

This update for MozillaFirefox fixes the following issues:

Firefox Extended Support Release 153.2.0 ESR MFSA 2026-85 (bsc#1278001):

  • CVE-2026-75874 (bmo#2039972) Sandbox escape in the Remote Settings Client component
  • CVE-2026-84118 (bmo#2057457) Use-after-free in the JavaScript: GC component
  • CVE-2026-84119 (bmo#2057817) Sandbox escape due to use-after-free in the DOM: Navigation component
  • CVE-2026-84120 (bmo#2058911) Use-after-free in the Audio/Video component
  • CVE-2026-84121 (bmo#2059018) Sandbox escape due to use-after-free in the DOM: Security
  • CVE-2026-84122 (bmo#2059965)
  • CVE-2026-84123 (bmo#2060047) Privilege escalation due to use-after-free in the Graphics: WebGPU component
  • CVE-2026-84124 (bmo#2061110) Use-after-free in the DOM: Core & HTML component
  • CVE-2026-84125 (bmo#2063871)
  • CVE-2026-74952 (bmo#2021757) Privilege escalation in the Application Update component
  • CVE-2026-84129 (bmo#2055028) Site isolation issue in the DOM: Navigation component
  • CVE-2026-84130 (bmo#2057834) Information disclosure in the Graphics: WebGPU component
  • CVE-2026-84131 (bmo#2060008) Privilege escalation due to invalid pointer in the Graphics
  • CVE-2026-84132 (bmo#2063020) Information disclosure in the Networking: HTTP component
  • CVE-2026-84133 (bmo#2032388) Site isolation issue in the DOM: Push Subscriptions component
  • CVE-2026-84134 (bmo#2044882) Other issue in the Profile Backup component
  • CVE-2026-84136 (bmo#2048699) Other issue in the DOM: Navigation component
  • CVE-2026-84137 (bmo#2051146) Spoofing issue in the DOM: Core & HTML component
  • CVE-2026-84139 (bmo#2060153) Clickjacking issue in the DOM: Events component
  • CVE-2026-84140 (bmo#2063780)
  • CVE-2026-84141 (bmo#2063994) Integer overflow in the Graphics: ImageLib component
  • CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107, bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088, bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109, bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301, bmo#2061325) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
  • CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624, bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726, bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013, bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661, bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144, bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199, bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495, bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775, bmo#2061799, bmo#2062395, bmo#2062404) Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
  • CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001, bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027, bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285, bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400, bmo#2062419) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
References

Affected packages

openSUSE:Leap 16.0 / MozillaFirefox

Package

Name
MozillaFirefox
Purl
pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.2.0-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "MozillaFirefox":  "153.2.0-160000.1.1",
            "MozillaFirefox-branding-upstream":  "153.2.0-160000.1.1",
            "MozillaFirefox-devel":  "153.2.0-160000.1.1",
            "MozillaFirefox-translations-common":  "153.2.0-160000.1.1",
            "MozillaFirefox-translations-other":  "153.2.0-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21853-1.json"