Opened 7 months ago

Closed 7 months ago

#22851 closed enhancement (duplicate)

firefox-140.8.0 spidermonkey

Reported by: Douglas R. Reno Owned by: blfs-book
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: critical Keywords:
Cc:

Description

New minor version

This contains 37 security fixes! This is in the JavaScript engine as well as Firefox itself, with numerous types of issues as well.

  • CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component (High)
  • CVE-2026-2758: Use-after-free in the JavaScript: GC component (High)
  • CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component (High)
  • CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component (High)
  • CVE-2026-2761: Sandbox escape in the Graphics: WebRender component (High)
  • CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component (High)
  • CVE-2026-2763: Use-after-free in the JavaScript Engine component (High)
  • CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component (High)
  • CVE-2026-2765: Use-after-free in the JavaScript Engine component (High)
  • CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component (High)
  • CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component (High)
  • CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component (High)
  • CVE-2026-2769: Use-after-free in the Storage: IndexedDB component (High)
  • CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component (High)
  • CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component (High)
  • CVE-2026-2772: Use-after-free in the Audio/Video: Playback component (High)
  • CVE-2026-2773: Incorrect boundary conditions in the Web Audio component (High)
  • CVE-2026-2774: Integer overflow in the Audio/Video component (High)
  • CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component (High)
  • CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software (High)
  • CVE-2026-2777: Privilege escalation in the Messaging System component (High)
  • CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component (High)
  • CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component (Moderate)
  • CVE-2026-2780: Privilege escalation in the Netmonitor component (Moderate)
  • CVE-2026-2781: Integer overflow in the Libraries component in NSS (Moderate)
  • CVE-2026-2782: Privilege escalation in the Netmonitor component (Moderate)
  • CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component (Moderate)
  • CVE-2026-2784: Mitigation bypass in the DOM: Security component (Moderate)
  • CVE-2026-2785: Invalid pointer in the JavaScript Engine component (Moderate)
  • CVE-2026-2786: Use-after-free in the JavaScript Engine component (Moderate)
  • CVE-2026-2787: Use-after-free in the DOM: Window and Location component (Moderate)
  • CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component (Moderate)
  • CVE-2026-2789: Use-after-free in the Graphics: ImageLib component (Moderate)
  • CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component (Low)
  • CVE-2026-2791: Mitigation bypass in the Networking: Cache component (Low)
  • CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 (High)
  • CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 (High)

Change History (3)

comment:1 by Xi Ruoyao, 7 months ago

Maybe we should make it 13.0? Firefox is end package and there are not so many packages depending on Spidermonkey (only gnome-shell{,-extensions}, gnome-maps, and gnome-weather IIRC).

comment:2 by Bruce Dubbs, 7 months ago

Milestone: 13.1 → 13.0

Yes, we need to update now.

comment:3 by zeckma, 7 months ago

Resolution: → duplicate
Status: new → closed

Duplicate of #22822. The previous Firefox ticket will be the one that covers this update and the SAs will be combined into one.

Note: See TracTickets for help on using tickets.