SUSE-SU-2026:23784-1: important: Security update for MozillaFirefox
SLE-SECURITY-UPDATES
null at suse.de
Mon Sep 21 08:42:58 UTC 2026
# Security update for MozillaFirefox
Announcement ID: SUSE-SU-2026:23784-1
Release Date: 2026-09-15T14:40:48Z
Rating: important
References:
* bsc#1278001
Cross-References:
* CVE-2026-74952
* CVE-2026-75874
* CVE-2026-84118
* CVE-2026-84119
* CVE-2026-84120
* CVE-2026-84121
* CVE-2026-84122
* CVE-2026-84123
* CVE-2026-84124
* CVE-2026-84125
* CVE-2026-84129
* CVE-2026-84130
* CVE-2026-84131
* CVE-2026-84132
* CVE-2026-84133
* CVE-2026-84134
* CVE-2026-84136
* CVE-2026-84137
* CVE-2026-84139
* CVE-2026-84140
* CVE-2026-84141
* CVE-2026-84143
* CVE-2026-84144
* CVE-2026-84145
CVSS scores:
* CVE-2026-74952 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-75874 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-84118 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84118 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84119 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-84119 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-84120 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84120 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84121 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-84121 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-84122 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84122 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84123 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-84123 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-84124 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84124 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84125 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84125 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-84129 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-84131 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-84131 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-84132 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-84133 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84134 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-84136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84137 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-84137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84139 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-84139 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-84144 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-84145 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-84145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products:
* SUSE Linux Enterprise Server 16.0
* SUSE Linux Enterprise Server for SAP applications 16.0
An update that solves 24 vulnerabilities can now be installed.
## Description:
This update for MozillaFirefox fixes the following issues:
Firefox Extended Support Release 153.2.0 ESR MFSA 2026-85 (bsc#1278001):
* CVE-2026-75874 (bmo#2039972) Sandbox escape in the Remote Settings Client
component
* CVE-2026-84118 (bmo#2057457) Use-after-free in the JavaScript: GC component
* CVE-2026-84119 (bmo#2057817) Sandbox escape due to use-after-free in the
DOM: Navigation component
* CVE-2026-84120 (bmo#2058911) Use-after-free in the Audio/Video component
* CVE-2026-84121 (bmo#2059018) Sandbox escape due to use-after-free in the
DOM: Security
* CVE-2026-84122 (bmo#2059965)
* CVE-2026-84123 (bmo#2060047) Privilege escalation due to use-after-free in
the Graphics: WebGPU component
* CVE-2026-84124 (bmo#2061110) Use-after-free in the DOM: Core & HTML
component
* CVE-2026-84125 (bmo#2063871)
* CVE-2026-74952 (bmo#2021757) Privilege escalation in the Application Update
component
* CVE-2026-84129 (bmo#2055028) Site isolation issue in the DOM: Navigation
component
* CVE-2026-84130 (bmo#2057834) Information disclosure in the Graphics: WebGPU
component
* CVE-2026-84131 (bmo#2060008) Privilege escalation due to invalid pointer in
the Graphics
* CVE-2026-84132 (bmo#2063020) Information disclosure in the Networking: HTTP
component
* CVE-2026-84133 (bmo#2032388) Site isolation issue in the DOM: Push
Subscriptions component
* CVE-2026-84134 (bmo#2044882) Other issue in the Profile Backup component
* CVE-2026-84136 (bmo#2048699) Other issue in the DOM: Navigation component
* CVE-2026-84137 (bmo#2051146) Spoofing issue in the DOM: Core & HTML
component
* CVE-2026-84139 (bmo#2060153) Clickjacking issue in the DOM: Events component
* CVE-2026-84140 (bmo#2063780)
* CVE-2026-84141 (bmo#2063994) Integer overflow in the Graphics: ImageLib
component
* CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, bmo#2054657,
bmo#2055007, bmo#2055681, bmo#2057107, bmo#2057108, bmo#2057114,
bmo#2058087, bmo#2058088, bmo#2058090, bmo#2058095, bmo#2058101,
bmo#2059109, bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301,
bmo#2061325) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2
and Firefox ESR 140.15
* CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624, bmo#2054625,
bmo#2054691, bmo#2054702, bmo#2054726, bmo#2054775, bmo#2055703,
bmo#2058006, bmo#2058013, bmo#2058085, bmo#2058098, bmo#2058627,
bmo#2058661, bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144,
bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199, bmo#2059205,
bmo#2061320, bmo#2061430, bmo#2061495, bmo#2061505, bmo#2061521,
bmo#2061532, bmo#2061775, bmo#2061799, bmo#2062395, bmo#2062404) Internally
found bugs fixed in Firefox 155 and Firefox ESR 153.2
* CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, bmo#2055678,
bmo#2055693, bmo#2055705, bmo#2058001, bmo#2058051, bmo#2058652,
bmo#2058660, bmo#2059027, bmo#2059139, bmo#2061220, bmo#2061242,
bmo#2061285, bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400,
bmo#2062419) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2,
Firefox ESR 140.15 and Firefox ESR 115.40
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-1684
* SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-1684
## Package List:
* SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
* MozillaFirefox-153.2.0-160000.1.1
* MozillaFirefox-translations-other-153.2.0-160000.1.1
* MozillaFirefox-debuginfo-153.2.0-160000.1.1
* MozillaFirefox-debugsource-153.2.0-160000.1.1
* MozillaFirefox-translations-common-153.2.0-160000.1.1
* SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
* MozillaFirefox-devel-153.2.0-160000.1.1
* SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64)
* MozillaFirefox-153.2.0-160000.1.1
* MozillaFirefox-translations-other-153.2.0-160000.1.1
* MozillaFirefox-debuginfo-153.2.0-160000.1.1
* MozillaFirefox-debugsource-153.2.0-160000.1.1
* MozillaFirefox-translations-common-153.2.0-160000.1.1
* SUSE Linux Enterprise Server 16.0 (noarch)
* MozillaFirefox-devel-153.2.0-160000.1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-74952.html
* https://www.suse.com/security/cve/CVE-2026-75874.html
* https://www.suse.com/security/cve/CVE-2026-84118.html
* https://www.suse.com/security/cve/CVE-2026-84119.html
* https://www.suse.com/security/cve/CVE-2026-84120.html
* https://www.suse.com/security/cve/CVE-2026-84121.html
* https://www.suse.com/security/cve/CVE-2026-84122.html
* https://www.suse.com/security/cve/CVE-2026-84123.html
* https://www.suse.com/security/cve/CVE-2026-84124.html
* https://www.suse.com/security/cve/CVE-2026-84125.html
* https://www.suse.com/security/cve/CVE-2026-84129.html
* https://www.suse.com/security/cve/CVE-2026-84130.html
* https://www.suse.com/security/cve/CVE-2026-84131.html
* https://www.suse.com/security/cve/CVE-2026-84132.html
* https://www.suse.com/security/cve/CVE-2026-84133.html
* https://www.suse.com/security/cve/CVE-2026-84134.html
* https://www.suse.com/security/cve/CVE-2026-84136.html
* https://www.suse.com/security/cve/CVE-2026-84137.html
* https://www.suse.com/security/cve/CVE-2026-84139.html
* https://www.suse.com/security/cve/CVE-2026-84140.html
* https://www.suse.com/security/cve/CVE-2026-84141.html
* https://www.suse.com/security/cve/CVE-2026-84143.html
* https://www.suse.com/security/cve/CVE-2026-84144.html
* https://www.suse.com/security/cve/CVE-2026-84145.html
* https://bugzilla.suse.com/show_bug.cgi?id=1278001
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260921/ceb349ac/attachment.htm>
More information about the sle-security-updates
mailing list