Mageia alert MGASA-2026-0345 (firefox, nspr, nss)
| From: | Mageia Updates <updates-announce@ml.mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2026-0345: Updated nspr, nss, & firefox packages fix security vulnerabilities | |
| Date: | Mon, 31 Aug 2026 18:22:56 +0200 | |
| Message-ID: | <20260831162256.BED4A9FEB0@duvel.mageia.org> | |
| Archive-link: | Article |
MGASA-2026-0345 - Updated nspr, nss, & firefox packages fix security vulnerabilities Publication date: 31 Aug 2026 URL: https://advisories.mageia.org/MGASA-2026-0345.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-74934, CVE-2026-74935, CVE-2026-74936, CVE-2026-74937, CVE-2026-74938, CVE-2026-74939, CVE-2026-74940, CVE-2026-74941, CVE-2026-74942, CVE-2026-74943, CVE-2026-74944, CVE-2026-74945, CVE-2026-74946, CVE-2026-74947, CVE-2026-74948, CVE-2026-74950, CVE-2026-74953, CVE-2026-74954, CVE-2026-74955, CVE-2026-74956, CVE-2026-74957, CVE-2026-74958, CVE-2026-74959, CVE-2026-74960, CVE-2026-74961, CVE-2026-74962, CVE-2026-74963, CVE-2026-74964, CVE-2026-74965, CVE-2026-74966, CVE-2026-74967, CVE-2026-74968, CVE-2026-74969, CVE-2026-74970, CVE-2026-74971, CVE-2026-74972, CVE-2026-74949, CVE-2026-74973, CVE-2026-74974, CVE-2026-74976, CVE-2026-74977, CVE-2026-74978, CVE-2026-74979, CVE-2026-74981, CVE-2026-74982, CVE-2026-74983, CVE-2026-74984, CVE-2026-74985, CVE-2026-74986, CVE-2026-74987, CVE-2026-74988, CVE-2026-74990 Description: Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74987) Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. (CVE-2026-74988) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74990) References: - https://bugs.mageia.org/show_bug.cgi?id=36123 - https://firefox-source-docs.mozilla.org/security/nss/rele... - https://github.com/mozilla/nspr/releases/tag/NSPR_4_40_RTM - https://www.firefox.com/en-US/firefox/140.14.0/releasenotes/ - https://www.firefox.com/en-US/firefox/153.1.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa202... - https://www.mozilla.org/en-US/security/advisories/mfsa202... - https://www.cve.org/CVERecord?id=CVE-2026-74934 - https://www.cve.org/CVERecord?id=CVE-2026-74935 - https://www.cve.org/CVERecord?id=CVE-2026-74936 - https://www.cve.org/CVERecord?id=CVE-2026-74937 - https://www.cve.org/CVERecord?id=CVE-2026-74938 - https://www.cve.org/CVERecord?id=CVE-2026-74939 - https://www.cve.org/CVERecord?id=CVE-2026-74940 - https://www.cve.org/CVERecord?id=CVE-2026-74941 - https://www.cve.org/CVERecord?id=CVE-2026-74942 - https://www.cve.org/CVERecord?id=CVE-2026-74943 - https://www.cve.org/CVERecord?id=CVE-2026-74944 - https://www.cve.org/CVERecord?id=CVE-2026-74945 - https://www.cve.org/CVERecord?id=CVE-2026-74946 - https://www.cve.org/CVERecord?id=CVE-2026-74947 - https://www.cve.org/CVERecord?id=CVE-2026-74948 - https://www.cve.org/CVERecord?id=CVE-2026-74950 - https://www.cve.org/CVERecord?id=CVE-2026-74953 - https://www.cve.org/CVERecord?id=CVE-2026-74954 - https://www.cve.org/CVERecord?id=CVE-2026-74955 - https://www.cve.org/CVERecord?id=CVE-2026-74956 - https://www.cve.org/CVERecord?id=CVE-2026-74957 - https://www.cve.org/CVERecord?id=CVE-2026-74958 - https://www.cve.org/CVERecord?id=CVE-2026-74959 - https://www.cve.org/CVERecord?id=CVE-2026-74960 - https://www.cve.org/CVERecord?id=CVE-2026-74961 - https://www.cve.org/CVERecord?id=CVE-2026-74962 - https://www.cve.org/CVERecord?id=CVE-2026-74963 - https://www.cve.org/CVERecord?id=CVE-2026-74964 - https://www.cve.org/CVERecord?id=CVE-2026-74965 - https://www.cve.org/CVERecord?id=CVE-2026-74966 - https://www.cve.org/CVERecord?id=CVE-2026-74967 - https://www.cve.org/CVERecord?id=CVE-2026-74968 - https://www.cve.org/CVERecord?id=CVE-2026-74969 - https://www.cve.org/CVERecord?id=CVE-2026-74970 - https://www.cve.org/CVERecord?id=CVE-2026-74971 - https://www.cve.org/CVERecord?id=CVE-2026-74972 - https://www.cve.org/CVERecord?id=CVE-2026-74949 - https://www.cve.org/CVERecord?id=CVE-2026-74973 - https://www.cve.org/CVERecord?id=CVE-2026-74974 - https://www.cve.org/CVERecord?id=CVE-2026-74976 - https://www.cve.org/CVERecord?id=CVE-2026-74977 - https://www.cve.org/CVERecord?id=CVE-2026-74978 - https://www.cve.org/CVERecord?id=CVE-2026-74979 - https://www.cve.org/CVERecord?id=CVE-2026-74981 - https://www.cve.org/CVERecord?id=CVE-2026-74982 - https://www.cve.org/CVERecord?id=CVE-2026-74983 - https://www.cve.org/CVERecord?id=CVE-2026-74984 - https://www.cve.org/CVERecord?id=CVE-2026-74985 - https://www.cve.org/CVERecord?id=CVE-2026-74986 - https://www.cve.org/CVERecord?id=CVE-2026-74987 - https://www.cve.org/CVERecord?id=CVE-2026-74988 - https://www.cve.org/CVERecord?id=CVE-2026-74990 SRPMS: - 10/core/nspr-4.40.0-1.mga10 - 10/core/nss-3.127.0-1.mga10 - 10/core/firefox-153.1.0-1.mga10 - 10/core/firefox-l10n-153.1.0-1.mga10 - 9/core/nspr-4.40.0-1.mga9 - 9/core/nss-3.127.0-1.mga9 - 9/core/firefox-140.14.0-1.mga9 - 9/core/firefox-l10n-140.14.0-1.mga9
