SUSE-SU-2026:23784-1: important: Security update for MozillaFirefox

SLE-SECURITY-UPDATES null at suse.de
Mon Sep 21 08:42:58 UTC 2026


# Security update for MozillaFirefox

Announcement ID: SUSE-SU-2026:23784-1  
Release Date: 2026-09-15T14:40:48Z  
Rating: important  
References:

  * bsc#1278001

  
Cross-References:

  * CVE-2026-74952
  * CVE-2026-75874
  * CVE-2026-84118
  * CVE-2026-84119
  * CVE-2026-84120
  * CVE-2026-84121
  * CVE-2026-84122
  * CVE-2026-84123
  * CVE-2026-84124
  * CVE-2026-84125
  * CVE-2026-84129
  * CVE-2026-84130
  * CVE-2026-84131
  * CVE-2026-84132
  * CVE-2026-84133
  * CVE-2026-84134
  * CVE-2026-84136
  * CVE-2026-84137
  * CVE-2026-84139
  * CVE-2026-84140
  * CVE-2026-84141
  * CVE-2026-84143
  * CVE-2026-84144
  * CVE-2026-84145

  
CVSS scores:

  * CVE-2026-74952 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-75874 ( NVD ):  10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  * CVE-2026-84118 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84118 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84119 ( SUSE ):  8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
  * CVE-2026-84119 ( NVD ):  9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  * CVE-2026-84120 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84120 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84121 ( SUSE ):  8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
  * CVE-2026-84121 ( NVD ):  9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  * CVE-2026-84122 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84122 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84123 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-84123 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-84124 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84124 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84125 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84125 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-84129 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84130 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-84131 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-84131 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-84132 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-84133 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84134 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84136 ( NVD ):  6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-84136 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84137 ( NVD ):  4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-84137 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84139 ( NVD ):  6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-84139 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84140 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84140 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84141 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84141 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84143 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84143 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-84144 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-84145 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-84145 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

  
Affected Products:

  * SUSE Linux Enterprise Server 16.0
  * SUSE Linux Enterprise Server for SAP applications 16.0

  
  
An update that solves 24 vulnerabilities can now be installed.

## Description:

This update for MozillaFirefox fixes the following issues:

Firefox Extended Support Release 153.2.0 ESR MFSA 2026-85 (bsc#1278001):

  * CVE-2026-75874 (bmo#2039972) Sandbox escape in the Remote Settings Client
    component
  * CVE-2026-84118 (bmo#2057457) Use-after-free in the JavaScript: GC component
  * CVE-2026-84119 (bmo#2057817) Sandbox escape due to use-after-free in the
    DOM: Navigation component
  * CVE-2026-84120 (bmo#2058911) Use-after-free in the Audio/Video component
  * CVE-2026-84121 (bmo#2059018) Sandbox escape due to use-after-free in the
    DOM: Security
  * CVE-2026-84122 (bmo#2059965)
  * CVE-2026-84123 (bmo#2060047) Privilege escalation due to use-after-free in
    the Graphics: WebGPU component
  * CVE-2026-84124 (bmo#2061110) Use-after-free in the DOM: Core & HTML
    component
  * CVE-2026-84125 (bmo#2063871)
  * CVE-2026-74952 (bmo#2021757) Privilege escalation in the Application Update
    component
  * CVE-2026-84129 (bmo#2055028) Site isolation issue in the DOM: Navigation
    component
  * CVE-2026-84130 (bmo#2057834) Information disclosure in the Graphics: WebGPU
    component
  * CVE-2026-84131 (bmo#2060008) Privilege escalation due to invalid pointer in
    the Graphics
  * CVE-2026-84132 (bmo#2063020) Information disclosure in the Networking: HTTP
    component
  * CVE-2026-84133 (bmo#2032388) Site isolation issue in the DOM: Push
    Subscriptions component
  * CVE-2026-84134 (bmo#2044882) Other issue in the Profile Backup component
  * CVE-2026-84136 (bmo#2048699) Other issue in the DOM: Navigation component
  * CVE-2026-84137 (bmo#2051146) Spoofing issue in the DOM: Core & HTML
    component
  * CVE-2026-84139 (bmo#2060153) Clickjacking issue in the DOM: Events component
  * CVE-2026-84140 (bmo#2063780)
  * CVE-2026-84141 (bmo#2063994) Integer overflow in the Graphics: ImageLib
    component
  * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, bmo#2054657,
    bmo#2055007, bmo#2055681, bmo#2057107, bmo#2057108, bmo#2057114,
    bmo#2058087, bmo#2058088, bmo#2058090, bmo#2058095, bmo#2058101,
    bmo#2059109, bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301,
    bmo#2061325) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2
    and Firefox ESR 140.15
  * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624, bmo#2054625,
    bmo#2054691, bmo#2054702, bmo#2054726, bmo#2054775, bmo#2055703,
    bmo#2058006, bmo#2058013, bmo#2058085, bmo#2058098, bmo#2058627,
    bmo#2058661, bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144,
    bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199, bmo#2059205,
    bmo#2061320, bmo#2061430, bmo#2061495, bmo#2061505, bmo#2061521,
    bmo#2061532, bmo#2061775, bmo#2061799, bmo#2062395, bmo#2062404) Internally
    found bugs fixed in Firefox 155 and Firefox ESR 153.2
  * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, bmo#2055678,
    bmo#2055693, bmo#2055705, bmo#2058001, bmo#2058051, bmo#2058652,
    bmo#2058660, bmo#2059027, bmo#2059139, bmo#2061220, bmo#2061242,
    bmo#2061285, bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400,
    bmo#2062419) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2,
    Firefox ESR 140.15 and Firefox ESR 115.40

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP applications 16.0  
    zypper in -t patch SUSE-SLES-16.0-1684

  * SUSE Linux Enterprise Server 16.0  
    zypper in -t patch SUSE-SLES-16.0-1684

## Package List:

  * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
    * MozillaFirefox-153.2.0-160000.1.1
    * MozillaFirefox-translations-other-153.2.0-160000.1.1
    * MozillaFirefox-debuginfo-153.2.0-160000.1.1
    * MozillaFirefox-debugsource-153.2.0-160000.1.1
    * MozillaFirefox-translations-common-153.2.0-160000.1.1
  * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
    * MozillaFirefox-devel-153.2.0-160000.1.1
  * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64)
    * MozillaFirefox-153.2.0-160000.1.1
    * MozillaFirefox-translations-other-153.2.0-160000.1.1
    * MozillaFirefox-debuginfo-153.2.0-160000.1.1
    * MozillaFirefox-debugsource-153.2.0-160000.1.1
    * MozillaFirefox-translations-common-153.2.0-160000.1.1
  * SUSE Linux Enterprise Server 16.0 (noarch)
    * MozillaFirefox-devel-153.2.0-160000.1.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-74952.html
  * https://www.suse.com/security/cve/CVE-2026-75874.html
  * https://www.suse.com/security/cve/CVE-2026-84118.html
  * https://www.suse.com/security/cve/CVE-2026-84119.html
  * https://www.suse.com/security/cve/CVE-2026-84120.html
  * https://www.suse.com/security/cve/CVE-2026-84121.html
  * https://www.suse.com/security/cve/CVE-2026-84122.html
  * https://www.suse.com/security/cve/CVE-2026-84123.html
  * https://www.suse.com/security/cve/CVE-2026-84124.html
  * https://www.suse.com/security/cve/CVE-2026-84125.html
  * https://www.suse.com/security/cve/CVE-2026-84129.html
  * https://www.suse.com/security/cve/CVE-2026-84130.html
  * https://www.suse.com/security/cve/CVE-2026-84131.html
  * https://www.suse.com/security/cve/CVE-2026-84132.html
  * https://www.suse.com/security/cve/CVE-2026-84133.html
  * https://www.suse.com/security/cve/CVE-2026-84134.html
  * https://www.suse.com/security/cve/CVE-2026-84136.html
  * https://www.suse.com/security/cve/CVE-2026-84137.html
  * https://www.suse.com/security/cve/CVE-2026-84139.html
  * https://www.suse.com/security/cve/CVE-2026-84140.html
  * https://www.suse.com/security/cve/CVE-2026-84141.html
  * https://www.suse.com/security/cve/CVE-2026-84143.html
  * https://www.suse.com/security/cve/CVE-2026-84144.html
  * https://www.suse.com/security/cve/CVE-2026-84145.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1278001

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260921/ceb349ac/attachment.htm>


More information about the sle-security-updates mailing list