Opened 7 months ago
Closed 7 months ago
#22851 closed enhancement (duplicate)
firefox-140.8.0 spidermonkey
| Reported by: | Douglas R. Reno | Owned by: | blfs-book |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | critical | Keywords: | |
| Cc: |
Description
New minor version
This contains 37 security fixes! This is in the JavaScript engine as well as Firefox itself, with numerous types of issues as well.
- CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component (High)
- CVE-2026-2758: Use-after-free in the JavaScript: GC component (High)
- CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component (High)
- CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component (High)
- CVE-2026-2761: Sandbox escape in the Graphics: WebRender component (High)
- CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component (High)
- CVE-2026-2763: Use-after-free in the JavaScript Engine component (High)
- CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component (High)
- CVE-2026-2765: Use-after-free in the JavaScript Engine component (High)
- CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component (High)
- CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component (High)
- CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component (High)
- CVE-2026-2769: Use-after-free in the Storage: IndexedDB component (High)
- CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component (High)
- CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component (High)
- CVE-2026-2772: Use-after-free in the Audio/Video: Playback component (High)
- CVE-2026-2773: Incorrect boundary conditions in the Web Audio component (High)
- CVE-2026-2774: Integer overflow in the Audio/Video component (High)
- CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component (High)
- CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software (High)
- CVE-2026-2777: Privilege escalation in the Messaging System component (High)
- CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component (High)
- CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component (Moderate)
- CVE-2026-2780: Privilege escalation in the Netmonitor component (Moderate)
- CVE-2026-2781: Integer overflow in the Libraries component in NSS (Moderate)
- CVE-2026-2782: Privilege escalation in the Netmonitor component (Moderate)
- CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component (Moderate)
- CVE-2026-2784: Mitigation bypass in the DOM: Security component (Moderate)
- CVE-2026-2785: Invalid pointer in the JavaScript Engine component (Moderate)
- CVE-2026-2786: Use-after-free in the JavaScript Engine component (Moderate)
- CVE-2026-2787: Use-after-free in the DOM: Window and Location component (Moderate)
- CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component (Moderate)
- CVE-2026-2789: Use-after-free in the Graphics: ImageLib component (Moderate)
- CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component (Low)
- CVE-2026-2791: Mitigation bypass in the Networking: Cache component (Low)
- CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 (High)
- CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 (High)
Change History (3)
comment:1 by , 7 months ago
comment:3 by , 7 months ago
| Resolution: | → duplicate |
|---|---|
| Status: | new → closed |
Duplicate of #22822. The previous Firefox ticket will be the one that covers this update and the SAs will be combined into one.
Note:
See TracTickets
for help on using tickets.

Maybe we should make it 13.0? Firefox is end package and there are not so many packages depending on Spidermonkey (only gnome-shell{,-extensions}, gnome-maps, and gnome-weather IIRC).