Opened 8 months ago

Closed 8 months ago

Last modified 8 months ago

#22635 closed enhancement (fixed)

firefox-140.7.0esr and js-140.7.0 (spidermonkey)

Reported by: Joe Locash Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Release notes not available yet.

Change History (7)

comment:1 by zeckma, 8 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by Bruce Dubbs, 8 months ago

Summary: firefox-140.7.0esr → firefox-140.7.0esr and js-140.7.0 (spidermonkey)

comment:3 by Joe Locash, 8 months ago

Priority: normal → high

Security fixes:

  • CVE-2026-0877: Mitigation bypass in the DOM: Security component (high)
  • CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
  • CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the Graphics component (high)
  • CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics component (high)
  • CVE-2026-0882: Use-after-free in the IPC component (high)
  • CVE-2025-14327: Spoofing issue in the Downloads Panel component (moderate)
  • CVE-2026-0883: Information disclosure in the Networking component (moderate)
  • CVE-2026-0884: Use-after-free in the JavaScript Engine component (moderate)
  • CVE-2026-0885: Use-after-free in the JavaScript: GC component (moderate)
  • CVE-2026-0886: Incorrect boundary conditions in the Graphics component (moderate)
  • CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer component (moderate)
  • CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop component (low)
  • CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 (high)

comment:4 by zeckma, 8 months ago

Fixed at 234326ec690b09a4dd2ec9982df0b959a39f775d. Leaving open for SA.

comment:5 by zeckma, 8 months ago

CVE-2026-0878, CVE-2026-0879, CVE-2026-0880, CVE-2026-0884, and CVE-2026-0885 fixed in SpiderMonkey.

comment:6 by zeckma, 8 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-072 and SA-12.4-073 issued.

comment:7 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.