Opened 6 months ago
Closed 4 months ago
#23111 closed enhancement (fixed)
firefox-140.11.0esr and js-140.11.0 (spidermonkey)
| Reported by: | (none) | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version
This includes three high severity security fixes.
- CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Graphics: Text component (High)
- CVE-2026-5731: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (High). Description: "Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code."
- CVE-2026-5734: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (High). Description: "Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code."
I discussed this and a couple of other problems with Zeckma earlier this morning. She's going to be taking a break for a couple days since it's her first day off from her job for a while. I will take care of this as a result and will aim to have it in as soon as I can.
Change History (16)
comment:1 by , 6 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 6 months ago
| Reporter: | removed |
|---|---|
| Summary: | firefox-140.9.1 spidermonkey → firefox-140.9.1esr and js-140.9.1 (spidermonkey) |
comment:3 by , 5 months ago
comment:4 by , 5 months ago
| Summary: | firefox-140.9.1esr and js-140.9.1 (spidermonkey) → firefox-140.10.0esr and js-140.10.0 (spidermonkey) |
|---|
comment:5 by , 5 months ago
Security fixes for 140.10.0ESR:
- CVE-2026-6746: Use-after-free in the DOM: Core & HTML component (high)
- CVE-2026-6747: Use-after-free in the WebRTC component (high)
- CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component (high)
- CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component (high)
- CVE-2026-6750: Privilege escalation in the Graphics: WebRender component (high)
- CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component (high)
- CVE-2026-6752: Incorrect boundary conditions in the WebRTC component (high)
- CVE-2026-6753: Incorrect boundary conditions in the WebRTC component (high)
- CVE-2026-6754: Use-after-free in the JavaScript Engine component (high)
- CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component (moderate)
- CVE-2026-6759: Use-after-free in the Widget: Cocoa component (moderate)
- CVE-2026-6761: Privilege escalation in the Networking component (moderate)
- CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component (moderate)
- CVE-2026-6763: Mitigation bypass in the File Handling component (moderate)
- CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component (moderate)
- CVE-2026-6765: Information disclosure in the Form Autofill component (moderate)
- CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS (moderate)
- CVE-2026-6767: Other issue in the Libraries component in NSS (moderate)
- CVE-2026-6769: Privilege escalation in the Debugger component (moderate)
- CVE-2026-6770: Other issue in the Storage: IndexedDB component (moderate)
- CVE-2026-6771: Mitigation bypass in the DOM: Security component (moderate)
- CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS (moderate)
- CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component (moderate)
- CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (high)
- CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 (high)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-32/
comment:6 by , 5 months ago
| Summary: | firefox-140.10.0esr and js-140.10.0 (spidermonkey) → firefox-140.10.1esr and js-140.10.1 (spidermonkey) |
|---|
Security fixes for 140.10.1ESR:
- CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component (high)
- CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component (moderate)
- CVE-2026-7322: Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 (critical)
- CVE-2026-7323: Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 (high)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-36/
comment:7 by , 5 months ago
For 140.10.1 the ffmpeg patch is no longer needed but they didn't fix ffmpeg8 support completely. Replace the patch with this sed:
sed -i '/so.61/i \ "libavcodec.so.62",' dom/media/platforms/ffmpeg/FFmpegRuntimeLinker.cpp
comment:8 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Reassigning per IRC discussion.
comment:10 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Summary: | firefox-140.10.1esr and js-140.10.1 (spidermonkey) → firefox-140.10.2esr and js-140.10.2 (spidermonkey) |
Security fixes for 140.10.2ESR:
- CVE-2026-8090: Use-after-free in the DOM: Networking component (high)
- CVE-2026-8094: Other issue in the WebRTC component (high)
- CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 (high)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-41/
comment:12 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Summary: | firefox-140.10.2esr and js-140.10.2 (spidermonkey) → firefox-140.11.0esr and js-140.11.0 (spidermonkey) |
New version. Release notes not available yet.
comment:14 by , 4 months ago
Security fixes for 140.11.0ESR:
- CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component (high)
- CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component (high)
- CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component (high)
- CVE-2026-8391: Other issue in the JavaScript Engine component (high)
- CVE-2026-8401: Sandbox escape in the Profile Backup component (high)
- CVE-2026-8949: Integer overflow in the Widget: Win32 component (moderate)
- CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component (moderate)
- CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component(moderate)
- CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component (moderate)
- CVE-2026-8955: Privilege escalation in the DOM: Workers component (moderate)
- CVE-2026-8956: Integer overflow in the Networking: JAR component (moderate)
- CVE-2026-8957: Privilege escalation in the Enterprise Policies component (moderate)
- CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component (moderate)
- CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component (moderate)
- CVE-2026-8961: Spoofing issue in the Form Autofill component (low)
- CVE-2026-8962: Mitigation bypass in the DOM: Security component (low)
- CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component(low)
- CVE-2026-8970: Privilege escalation in the Security component (low)
- CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 (moderate)
- CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 (hight)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-48/
comment:15 by , 4 months ago
I'd suggest if there's a new release when the ticket for a prior one is still open for SA, create a new ticket instead of reusing the existing one. Otherwise it's really confusing (esp. when there are multiple "Fixes #xxxxx" entries in changelog for one ticket).
comment:16 by , 4 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
SA-13.0-072 issued for Spidermonkey
SA-13.0-073 issued for Firefox

This is now at 140.10.0esr.