Описание
Security update for MozillaFirefox
This update for MozillaFirefox fixes the following issue:
Update to Firefox Extended Support Release 140.10.0 ESR (bsc#1262230, MFSA 2026-32):
- CVE-2026-6746: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-6747: Use-after-free in the WebRTC component.
- CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component.
- CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component.
- CVE-2026-6750: Privilege escalation in the Graphics: WebRender component.
- CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component.
- CVE-2026-6752: Incorrect boundary conditions in the WebRTC component.
- CVE-2026-6753: Incorrect boundary conditions in the WebRTC component.
- CVE-2026-6754: Use-after-free in the JavaScript Engine component.
- CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component.
- CVE-2026-6759: Use-after-free in the Widget: Cocoa component.
- CVE-2026-6761: Privilege escalation in the Networking component.
- CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component.
- CVE-2026-6763: Mitigation bypass in the File Handling component.
- CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component.
- CVE-2026-6765: Information disclosure in the Form Autofill component.
- CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS.
- CVE-2026-6767: Other issue in the Libraries component in NSS.
- CVE-2026-6769: Privilege escalation in the Debugger component.
- CVE-2026-6770: Other issue in the Storage: IndexedDB component.
- CVE-2026-6771: Mitigation bypass in the DOM: Security component.
- CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS.
- CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component.
- CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150.
- CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150.
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Ссылки
- Link for SUSE-SU-2026:1650-1
- E-Mail link for SUSE-SU-2026:1650-1
- SUSE Security Ratings
- SUSE Bug 1262230
- SUSE CVE CVE-2026-6746 page
- SUSE CVE CVE-2026-6747 page
- SUSE CVE CVE-2026-6748 page
- SUSE CVE CVE-2026-6749 page
- SUSE CVE CVE-2026-6750 page
- SUSE CVE CVE-2026-6751 page
- SUSE CVE CVE-2026-6752 page
- SUSE CVE CVE-2026-6753 page
- SUSE CVE CVE-2026-6754 page
- SUSE CVE CVE-2026-6757 page
- SUSE CVE CVE-2026-6759 page
- SUSE CVE CVE-2026-6761 page
- SUSE CVE CVE-2026-6762 page
- SUSE CVE CVE-2026-6763 page
- SUSE CVE CVE-2026-6764 page
- SUSE CVE CVE-2026-6765 page
Описание
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6746
- SUSE Bug 1262230
Описание
Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6747
- SUSE Bug 1262230
Описание
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6748
- SUSE Bug 1262230
Описание
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6749
- SUSE Bug 1262230
Описание
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6750
- SUSE Bug 1262230
Описание
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6751
- SUSE Bug 1262230
Описание
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6752
- SUSE Bug 1262230
Описание
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6753
- SUSE Bug 1262230
Описание
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6754
- SUSE Bug 1262230
Описание
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6757
- SUSE Bug 1262230
Описание
Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6759
- SUSE Bug 1262230
Описание
Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6761
- SUSE Bug 1262230
Описание
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6762
- SUSE Bug 1262230
Описание
Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6763
- SUSE Bug 1262230
Описание
Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6764
- SUSE Bug 1262230
Описание
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6765
- SUSE Bug 1262230
Описание
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6766
- SUSE Bug 1262230
Описание
Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6767
- SUSE Bug 1262230
Описание
Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6769
- SUSE Bug 1262230
Описание
Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6770
- SUSE Bug 1262230
Описание
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6771
- SUSE Bug 1262230
Описание
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6772
- SUSE Bug 1262230
Описание
Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6776
- SUSE Bug 1262230
Описание
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6785
- SUSE Bug 1262230
Описание
Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Затронутые продукты
Ссылки
- CVE-2026-6786
- SUSE Bug 1262230