Opened 6 weeks ago

Closed 6 weeks ago

#23769 closed enhancement (fixed)

spidermonkey (js) 140.14.0esr

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: high Keywords:
Cc:

Description

These are the security fixes related to js in the Firefox advisory instead of listing all 31:

  • CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component (high)
  • CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component (low)

​https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/

Change History (2)

comment:1 by Joe Locash, 6 weeks ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at a94c733b1d. Leaving open for SA.

comment:2 by Bruce Dubbs, 6 weeks ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-204 has been issued.

Note: See TracTickets for help on using tickets.