Opened 8 months ago

Closed 7 months ago

#22822 closed enhancement (fixed)

firefox-140.8.0esr and js-140.8.0 (spidermonkey)

Reported by: Bruce Dubbs Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (7)

comment:1 by zeckma, 8 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by zeckma, 7 months ago

Fixes CVE-2026-2447 for bundled libvpx. More information can be found here: https://wiki.linuxfromscratch.org/blfs/ticket/22827.

comment:3 by zeckma, 7 months ago

Priority: normal → high

comment:4 by zeckma, 7 months ago

Fixed at 72a9117141fb4efed1227d343e8538ba3214b644. Spidermonkey should be unaffected by the security fix but it was still brought up to the same version as Firefox.

comment:5 by Joe Locash, 7 months ago

Summary: firefox-140.7.1esr and js-140.7.1 (spidermonkey) → firefox-140.8.0esr and js-140.8.0 (spidermonkey)

Now at 140.8.0esr. This update contains 37 CVE fixes!

Security fixes:

  • CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component (high)
  • CVE-2026-2758: Use-after-free in the JavaScript: GC component (high)
  • CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component (high)
  • CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component (high)
  • CVE-2026-2761: Sandbox escape in the Graphics: WebRender component (high)
  • CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component (high)
  • CVE-2026-2763: Use-after-free in the JavaScript Engine component (high)
  • CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component (high)
  • CVE-2026-2765: Use-after-free in the JavaScript Engine component (high)
  • CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component (high)
  • CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component (high)
  • CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component (high)
  • CVE-2026-2769: Use-after-free in the Storage: IndexedDB component (high)
  • CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component (high)
  • CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component (high)
  • CVE-2026-2772: Use-after-free in the Audio/Video: Playback component (high)
  • CVE-2026-2773: Incorrect boundary conditions in the Web Audio component (high)
  • CVE-2026-2774: Integer overflow in the Audio/Video component (high)
  • CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component (high)
  • CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software (high)
  • CVE-2026-2777: Privilege escalation in the Messaging System component (high)
  • CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component (high)
  • CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component (moderate)
  • CVE-2026-2780: Privilege escalation in the Netmonitor component (moderate)
  • CVE-2026-2781: Integer overflow in the Libraries component in NSS (moderate)
  • CVE-2026-2782: Privilege escalation in the Netmonitor component (moderate)
  • CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component (moderate)
  • CVE-2026-2784: Mitigation bypass in the DOM: Security component (moderate)
  • CVE-2026-2785: Invalid pointer in the JavaScript Engine component (moderate)
  • CVE-2026-2786: Use-after-free in the JavaScript Engine component (moderate)
  • CVE-2026-2787: Use-after-free in the DOM: Window and Location component (moderate)
  • CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component (moderate)
  • CVE-2026-2789: Use-after-free in the Graphics: ImageLib component (moderate)
  • CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component (low)
  • CVE-2026-2791: Mitigation bypass in the Networking: Cache component (low)
  • CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 (high)
  • CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 (high)

​https://www.mozilla.org/en-US/security/advisories/mfsa2026-15/

comment:6 by zeckma, 7 months ago

Fixed at 9c673aba7a2c58befb684563ea02da3f06343ef4. Leaving open for SA.

comment:7 by zeckma, 7 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-103 and SA-12.4-104 issued.

Note: See TracTickets for help on using tickets.