SUSE-CU-2026:10857-1: Security update of suse/kiosk/firefox-esr
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Sep 19 08:25:55 UTC 2026
SUSE Container Update Advisory: suse/kiosk/firefox-esr
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10857-1
Container Tags : suse/kiosk/firefox-esr:153.3 , suse/kiosk/firefox-esr:153.3-75.41 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest
Container Release : 75.41
Severity : important
Type : security
References : 1280371 CVE-2026-92005 CVE-2026-92006 CVE-2026-92007 CVE-2026-92008
CVE-2026-92009 CVE-2026-92010 CVE-2026-92011 CVE-2026-92012 CVE-2026-92013
CVE-2026-92015 CVE-2026-92016 CVE-2026-92017 CVE-2026-92018 CVE-2026-92019
CVE-2026-92020 CVE-2026-92022 CVE-2026-92023 CVE-2026-92024 CVE-2026-92025
CVE-2026-92026 CVE-2026-92027 CVE-2026-92028 CVE-2026-92029 CVE-2026-92030
CVE-2026-92031 CVE-2026-92032 CVE-2026-92035 CVE-2026-92038 CVE-2026-92039
CVE-2026-92041 CVE-2026-92042 CVE-2026-92043 CVE-2026-92044 CVE-2026-92045
CVE-2026-92046 CVE-2026-92047 CVE-2026-92048 CVE-2026-92049 CVE-2026-92052
CVE-2026-92053 CVE-2026-92054 CVE-2026-92055 CVE-2026-92056 CVE-2026-92057
CVE-2026-92058 CVE-2026-92059 CVE-2026-92060 CVE-2026-92062 CVE-2026-92064
CVE-2026-92065 CVE-2026-92067 CVE-2026-92068 CVE-2026-92069 CVE-2026-92070
CVE-2026-92071 CVE-2026-92072 CVE-2026-92073 CVE-2026-92074 CVE-2026-92075
CVE-2026-92076 CVE-2026-92077 CVE-2026-92078 CVE-2026-92079
-----------------------------------------------------------------
The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4264-1
Released: Fri Sep 18 15:54:08 2026
Summary: Security update for MozillaFirefox
Type: security
Severity: important
References: 1280371,CVE-2026-92005,CVE-2026-92006,CVE-2026-92007,CVE-2026-92008,CVE-2026-92009,CVE-2026-92010,CVE-2026-92011,CVE-2026-92012,CVE-2026-92013,CVE-2026-92015,CVE-2026-92016,CVE-2026-92017,CVE-2026-92018,CVE-2026-92019,CVE-2026-92020,CVE-2026-92022,CVE-2026-92023,CVE-2026-92024,CVE-2026-92025,CVE-2026-92026,CVE-2026-92027,CVE-2026-92028,CVE-2026-92029,CVE-2026-92030,CVE-2026-92031,CVE-2026-92032,CVE-2026-92035,CVE-2026-92038,CVE-2026-92039,CVE-2026-92041,CVE-2026-92042,CVE-2026-92043,CVE-2026-92044,CVE-2026-92045,CVE-2026-92046,CVE-2026-92047,CVE-2026-92048,CVE-2026-92049,CVE-2026-92052,CVE-2026-92053,CVE-2026-92054,CVE-2026-92055,CVE-2026-92056,CVE-2026-92057,CVE-2026-92058,CVE-2026-92059,CVE-2026-92060,CVE-2026-92062,CVE-2026-92064,CVE-2026-92065,CVE-2026-92067,CVE-2026-92068,CVE-2026-92069,CVE-2026-92070,CVE-2026-92071,CVE-2026-92072,CVE-2026-92073,CVE-2026-92074,CVE-2026-92075,CVE-2026-92076,CVE-2026-92077,CVE-2026-92078,CVE-2026-92079
This update for MozillaFirefox fixes the following issues:
Update to Firefox Extended Support Release 153.3.0 ESRi (MFSA 2026-93, bsc#1280371)
- CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component.
- CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92015: Privilege escalation in the WebExtensions component.
- CVE-2026-92016: Use-after-free in the Disability Access APIs component.
- CVE-2026-92017: Privilege escalation in the DOM: Service Workers component.
- CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component.
- CVE-2026-92019: Mitigation bypass in the Remote Settings Client component.
- CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component.
- CVE-2026-92022: Use-after-free in the DOM: HTML Parser component.
- CVE-2026-92023: Use-after-free in the XML component.
- CVE-2026-92024: Use-after-free in the SVG component.
- CVE-2026-92025: Use-after-free in the DOM: Navigation component.
- CVE-2026-92026: Use-after-free in the Networking component.
- CVE-2026-92027: Use-after-free in the DOM: Streams component.
- CVE-2026-92028: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-92029: Use-after-free in the SVG component.
- CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component.
- CVE-2026-92031: Information disclosure in the Graphics: ImageLib component.
- CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component.
- CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component.
- CVE-2026-92038: Mitigation bypass in the Remote Settings Client component.
- CVE-2026-92039: Mitigation bypass in the DOM: Notifications component.
- CVE-2026-92041: Mitigation bypass in the DOM: Networking component.
- CVE-2026-92042: Race condition in the DOM: Content Processes component.
- CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component.
- CVE-2026-92044: Information disclosure in the Networking: HTTP component.
- CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component.
- CVE-2026-92046: Use-after-free in the Graphics component.
- CVE-2026-92047: Privilege escalation in the Crash Reporting component.
- CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
- CVE-2026-92049: Use-after-free in the Widget: Win32 component.
- CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component.
- CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component.
- CVE-2026-92054: Privilege escalation in the Memory component.
- CVE-2026-92055: Privilege escalation in the DevTools component.
- CVE-2026-92056: Use-after-free in the Graphics: Text component.
- CVE-2026-92057: Mitigation bypass in the Enterprise Policies component.
- CVE-2026-92058: Use-after-free in the Graphics component.
- CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component.
- CVE-2026-92060: Use-after-free in the Internationalization component.
- CVE-2026-92062: Privilege escalation in the Session Restore component.
- CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
- CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
- CVE-2026-92067: Use-after-free in the Widget: Gtk component.
- CVE-2026-92068: Site isolation issue in the Reader Mode component.
- CVE-2026-92069: Spoofing issue in the DOM: Navigation component.
- CVE-2026-92070: Information disclosure in the Networking component.
- CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
- CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component.
- CVE-2026-92073: Privilege escalation in the Enterprise Policies component.
- CVE-2026-92074: Mitigation bypass in the Popup Blocker component.
- CVE-2026-92075: Mitigation bypass in the Networking component.
- CVE-2026-92076: Incorrect boundary conditions in the Networking component.
- CVE-2026-92077: Denial-of-service in the SVG component.
- CVE-2026-92078: Denial-of-service in the Security component.
- CVE-2026-92079: Mitigation bypass in the Widget: Win32 component.
The following package changes have been done:
- MozillaFirefox-153.3.0-150400.157.8.1 updated
More information about the sle-container-updates
mailing list