SUSE-CU-2026:6899-1: Security update of suse/kiosk/firefox-esr

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 10 08:10:25 UTC 2026


SUSE Container Update Advisory: suse/kiosk/firefox-esr
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:6899-1
Container Tags        : suse/kiosk/firefox-esr:140.12 , suse/kiosk/firefox-esr:140.12-74.15 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest
Container Release     : 74.15
Severity              : important
Type                  : security
References            : 1268071 1269226 CVE-2026-12289 CVE-2026-12290 CVE-2026-12291
                        CVE-2026-12292 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297
                        CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304 CVE-2026-12305
                        CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309 CVE-2026-12310
                        CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315
                        CVE-2026-12324 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329
                        CVE-2026-12330 
-----------------------------------------------------------------

The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2814-1
Released:    Thu Jul  9 14:25:54 2026
Summary:     Security update for MozillaFirefox
Type:        security
Severity:    important
References:  1268071,1269226,CVE-2026-12289,CVE-2026-12290,CVE-2026-12291,CVE-2026-12292,CVE-2026-12294,CVE-2026-12295,CVE-2026-12296,CVE-2026-12297,CVE-2026-12298,CVE-2026-12299,CVE-2026-12302,CVE-2026-12304,CVE-2026-12305,CVE-2026-12306,CVE-2026-12307,CVE-2026-12308,CVE-2026-12309,CVE-2026-12310,CVE-2026-12311,CVE-2026-12312,CVE-2026-12313,CVE-2026-12314,CVE-2026-12315,CVE-2026-12324,CVE-2026-12325,CVE-2026-12327,CVE-2026-12328,CVE-2026-12329,CVE-2026-12330
This update for MozillaFirefox fixes the following issues:

- Removed obsolete mozilla-nss-certs and recommends p11-kit-nss-trust (bsc#1269226)

Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071):

- CVE-2026-12289: Privilege escalation in the Graphics: WebRender component.
- CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12291: Use-after-free in the Networking: HTTP component.
- CVE-2026-12292: Incorrect boundary conditions in the Web Audio component.
- CVE-2026-12294: Sandbox escape in the DOM: Workers component.
- CVE-2026-12295: Sandbox escape in the DOM: Navigation component.
- CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component.
- CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component.
- CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component.
- CVE-2026-12302: Mitigation bypass in the DOM: Security component.
- CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component.
- CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component.
- CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component.
- CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12315: Mitigation bypass in the DOM: Security component.
- CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component.
- CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird
  152.
- CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox
  152 and Thunderbird 152.
- CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12330: Incorrect boundary conditions in the Internationalization component.


The following package changes have been done:

- mozilla-nss-certs-3.112.5-150400.3.69.2 added
- MozillaFirefox-140.12.0-150200.152.245.1 updated
- p11-kit-0.23.22-150500.8.3.1 removed
- p11-kit-nss-trust-0.23.22-150500.8.3.1 removed


More information about the sle-container-updates mailing list