Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20621-1

Опубликовано: 23 апр. 2026
Источник: suse-cvrf

Описание

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Update to Firefox Extended Support Release 140.10.0 ESR.

  • MFSA 2026-32 (bsc#1262230):
  • CVE-2026-6746: Use-after-free in the DOM: Core & HTML component
  • CVE-2026-6747: Use-after-free in the WebRTC component
  • CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component
  • CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component
  • CVE-2026-6750: Privilege escalation in the Graphics: WebRender component
  • CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component
  • CVE-2026-6752: Incorrect boundary conditions in the WebRTC component
  • CVE-2026-6753: Incorrect boundary conditions in the WebRTC component
  • CVE-2026-6754: Use-after-free in the JavaScript Engine component
  • CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component
  • CVE-2026-6759: Use-after-free in the Widget: Cocoa component
  • CVE-2026-6761: Privilege escalation in the Networking component
  • CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component
  • CVE-2026-6763: Mitigation bypass in the File Handling component
  • CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component
  • CVE-2026-6765: Information disclosure in the Form Autofill component
  • CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS
  • CVE-2026-6767: Other issue in the Libraries component in NSS
  • CVE-2026-6769: Privilege escalation in the Debugger component
  • CVE-2026-6770: Other issue in the Storage: IndexedDB component
  • CVE-2026-6771: Mitigation bypass in the DOM: Security component
  • CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS
  • CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component
  • CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
  • CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150

Список пакетов

openSUSE Leap 16.0
MozillaFirefox-140.10.0-160000.1.1
MozillaFirefox-branding-upstream-140.10.0-160000.1.1
MozillaFirefox-devel-140.10.0-160000.1.1
MozillaFirefox-translations-common-140.10.0-160000.1.1
MozillaFirefox-translations-other-140.10.0-160000.1.1

Описание

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки

Описание

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.


Затронутые продукты
openSUSE Leap 16.0:MozillaFirefox-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-branding-upstream-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-devel-140.10.0-160000.1.1
openSUSE Leap 16.0:MozillaFirefox-translations-common-140.10.0-160000.1.1

Ссылки
Уязвимость openSUSE-SU-2026:20621-1