Opened 4 weeks ago

Closed 4 weeks ago

#23624 closed enhancement (fixed)

firefox-153.0esr

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 98-Security
Component: BOOK Version: git
Severity: high Keywords:
Cc:

Description

New majore version.

Change History (8)

comment:1 by Xi Ruoyao, 4 weeks ago

I plan to switch spidermonkey to use mach instead of configure as in this version we cannot test the package with the latter.

comment:2 by Xi Ruoyao, 4 weeks ago

Anyway spidermonkey needs to wait until gjs is adapted: https://gitlab.gnome.org/GNOME/gjs/-/work_items/740

comment:3 by Xi Ruoyao, 4 weeks ago

Summary: firefox-153.0esr and js-153.0 (spidermonkey)firefox-153.0esr

Split spidermonkey to #23631 as it's unlikely to be included in the upcoming BLFS release.

comment:4 by Joe Locash, 4 weeks ago

For changes see: https://www.firefox.com/en-US/firefox/153.0/releasenotes/

Security fixes:

  • CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component (high)
  • CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component (high)
  • CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component (high)
  • CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component (high)
  • CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component (high)
  • CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component (high)
  • CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component (high)
  • CVE-2026-16365: Privilege escalation in the DOM: Workers component (high)
  • CVE-2026-16366: Privilege escalation in the DOM: Navigation component (high)
  • CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component (high)
  • CVE-2026-16354: Information disclosure in the Graphics: ImageLib component (high)
  • CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component (high)
  • CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component (high)
  • CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component (high)
  • CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component (high)
  • CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component (high)
  • CVE-2026-16357: Incorrect boundary conditions in the Graphics component (high)
  • CVE-2026-16370: Mitigation bypass in the DOM: Networking component (moderate)
  • CVE-2026-16371: Privilege escalation in the DOM: Navigation component (moderate)
  • CVE-2026-16372: Privilege escalation in the DOM: Content Processes component (moderate)
  • CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android (moderate)
  • CVE-2026-16374: Information disclosure in the Framework component in DevTools (moderate)
  • CVE-2026-16375: Site isolation issue in the Networking: HTTP component (moderate)
  • CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component (moderate)
  • CVE-2026-16377: Mitigation bypass in the PDF Viewer component (moderate)
  • CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component (moderate)
  • CVE-2026-16379: Privilege escalation in the DOM: Content Processes component (moderate)
  • CVE-2026-16358: Site isolation issue in the Graphics: WebRender component (moderate)
  • CVE-2026-16380: Mitigation bypass in the Networking component (moderate)
  • CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component (moderate)
  • CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component (moderate)
  • CVE-2026-16383: Mitigation bypass in the DOM: Networking component (moderate)
  • CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component (moderate)
  • CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component (moderate)
  • CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component (moderate)
  • CVE-2026-16387: Site isolation issue in the Networking component (moderate)
  • CVE-2026-16388: Sandbox escape in the DOM: Networking component (moderate)
  • CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS (moderate)
  • CVE-2026-16390: Mitigation bypass in the Enterprise Policies component (moderate)
  • CVE-2026-16391: Information disclosure in the Storage: IndexedDB component (moderate)
  • CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component (moderate)
  • CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component (moderate)
  • CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component (moderate)
  • CVE-2026-16394: Mitigation bypass in the DOM: Security component (moderate)
  • CVE-2026-16395: Integer overflow in the Audio/Video component (moderate)
  • CVE-2026-16396: Privilege escalation in WebExtensions (moderate)
  • CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android (moderate)
  • CVE-2026-16398: Site isolation issue in the Graphics component (moderate)
  • CVE-2026-16399: Site isolation issue in the DOM: Navigation component (moderate)
  • CVE-2026-16400: Information disclosure in the DOM: Security component (moderate)
  • CVE-2026-16401: Privilege escalation in the Data Loss Prevention component (moderate)
  • CVE-2026-16402: Integer overflow in the Graphics: ImageLib component (moderate)
  • CVE-2026-16403: Spoofing issue in the Address Bar component (low)
  • CVE-2026-16404: Spoofing issue in Firefox for Android (low)
  • CVE-2026-16405: Information disclosure in the Networking: WebSockets component (low)
  • CVE-2026-16406: Mitigation bypass in the Networking component (low)
  • CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component (low)
  • CVE-2026-16408: Integer overflow in the Audio/Video: Playback component (low)
  • CVE-2026-16409: Invalid pointer in the Security: PSM component (low)
  • CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component (low)
  • CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (high)
  • CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (high)

https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/

comment:5 by Joe Locash, 4 weeks ago

Priority: normalhigh
Severity: normalhigh

comment:6 by Joe Locash, 4 weeks ago

Owner: changed from blfs-book to Joe Locash
Status: newassigned

comment:7 by Joe Locash, 4 weeks ago

Milestone: 13.198-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assignednew

Fixed at c83ad5b6a2. Leaving open for SA.

comment:8 by Bruce Dubbs, 4 weeks ago

Resolution: fixed
Status: newclosed

Advisory sa-13.0-178 has been issued.

Note: See TracTickets for help on using tickets.