gpp_maybe Security update for mozillafirefox
SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1649


This update for MozillaFirefox fixes the following issue: Update to Firefox Extended Support Release 140.10.0 ESR (bsc#1262230, MFSA 2026-32): - CVE-2026-6746: Use-after-free in the DOM: Core & HTML component. - CVE-2026-6747: Use-after-free in the WebRTC component. - CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component. - CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. - CVE-2026-6750: Privilege escalation in the Graphics: WebRender component. - CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component. - CVE-2026-6752: Incorrect boundary conditions in the WebRTC component. - CVE-2026-6753: Incorrect boundary conditions in the WebRTC component. - CVE-2026-6754: Use-after-free in the JavaScript Engine component. - CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component. - CVE-2026-6759: Use-after-free in the Widget: Cocoa component. - CVE-2026-6761: Privilege escalation in the Networking component. - CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component. - CVE-2026-6763: Mitigation bypass in the File Handling component. - CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component. - CVE-2026-6765: Information disclosure in the Form Autofill component. - CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS. - CVE-2026-6767: Other issue in the Libraries component in NSS. - CVE-2026-6769: Privilege escalation in the Debugger component. - CVE-2026-6770: Other issue in the Storage: IndexedDB component. - CVE-2026-6771: Mitigation bypass in the DOM: Security component. - CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS. - CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component. - CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150. - CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150.


cloud_download Downloads

Desktop Applications Module 15.7 aarch64
Desktop Applications Module 15.7 ppc64le
Desktop Applications Module 15.7 s390x
Desktop Applications Module 15.7 x86_64