SUSE-CU-2026:7402-1: Security update of suse/kiosk/firefox-esr

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Mon Jul 27 07:26:52 UTC 2026


SUSE Container Update Advisory: suse/kiosk/firefox-esr
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7402-1
Container Tags        : suse/kiosk/firefox-esr:140.13 , suse/kiosk/firefox-esr:140.13-74.34 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest
Container Release     : 74.34
Severity              : critical
Type                  : security
References            : 1255451 1271649 CVE-2025-59529 CVE-2026-15718 CVE-2026-15719
                        CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353
                        CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358
                        CVE-2026-16359 CVE-2026-16360 CVE-2026-16361 CVE-2026-16362 CVE-2026-16363
                        CVE-2026-16368 CVE-2026-16369 CVE-2026-16371 CVE-2026-16374 CVE-2026-16375
                        CVE-2026-16377 CVE-2026-16379 CVE-2026-16381 CVE-2026-16383 CVE-2026-16387
                        CVE-2026-16390 CVE-2026-16391 CVE-2026-16396 CVE-2026-16405 CVE-2026-16412
-----------------------------------------------------------------

The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3218-1
Released:    Thu Jul 23 19:34:12 2026
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1255451,CVE-2025-59529
This update for avahi fixes the following issue:

- CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3221-1
Released:    Thu Jul 23 19:39:03 2026
Summary:     Security update for MozillaFirefox
Type:        security
Severity:    critical
References:  1271649,CVE-2026-15718,CVE-2026-15719,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16361,CVE-2026-16362,CVE-2026-16363,CVE-2026-16368,CVE-2026-16369,CVE-2026-16371,CVE-2026-16374,CVE-2026-16375,CVE-2026-16377,CVE-2026-16379,CVE-2026-16381,CVE-2026-16383,CVE-2026-16387,CVE-2026-16390,CVE-2026-16391,CVE-2026-16396,CVE-2026-16405,CVE-2026-16412
This update for MozillaFirefox fixes the following issue:

- Firefox Extended Support Release 140.13.0 ESR (MFSA 2026-70, bsc#1271649):

- CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component.
- CVE-2026-15719: Site isolation issue in the DOM: Navigation component.
- CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component.
- CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component.
- CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component.
- CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component.
- CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component.
- CVE-2026-16354: Information disclosure in the Graphics: ImageLib component.
- CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component.
- CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component.
- CVE-2026-16357: Incorrect boundary conditions in the Graphics component.
- CVE-2026-16358: Site isolation issue in the Graphics: WebRender component.
- CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component.
- CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153.
- CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13.
- CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component.
- CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component.
- CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component.
- CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component.
- CVE-2026-16371: Privilege escalation in the DOM: Navigation component.
- CVE-2026-16374: Information disclosure in the Framework component in DevTools.
- CVE-2026-16375: Site isolation issue in the Networking: HTTP component.
- CVE-2026-16377: Mitigation bypass in the PDF Viewer component.
- CVE-2026-16379: Privilege escalation in the DOM: Content Processes component.
- CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component.
- CVE-2026-16383: Mitigation bypass in the DOM: Networking component.
- CVE-2026-16387: Site isolation issue in the Networking component.
- CVE-2026-16390: Mitigation bypass in the Enterprise Policies component.
- CVE-2026-16391: Information disclosure in the Storage: IndexedDB component.
- CVE-2026-16396: Privilege escalation in WebExtensions.
- CVE-2026-16405: Information disclosure in the Networking: WebSockets component.
- CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153.


The following package changes have been done:

- libavahi-common3-0.8-150600.15.21.1 updated
- libavahi-client3-0.8-150600.15.21.1 updated
- MozillaFirefox-140.13.0-150200.152.248.1 updated
- container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated


More information about the sle-container-updates mailing list