Advisories ยป MGASA-2026-0145

Updated firefox & thunderbird packages fix security vulnerabilities

Publication date: 16 May 2026
Modification date: 16 May 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-62813 , CVE-2026-32776 , CVE-2026-32777 , CVE-2026-32778 , CVE-2026-8090 , CVE-2026-8092 , CVE-2026-8094

Description

LZ4 compression library issue. (CVE-2025-62813)
libexpat before 2.7.5 allows a NULL pointer dereference with empty
external parameter entity content. (CVE-2026-32776)
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
(CVE-2026-32777)
libexpat before 2.7.5 allows a NULL pointer dereference in the function
setContext on retry after an earlier ouf-of-memory condition.
(CVE-2026-32778)
Use-after-free in the DOM: Networking component. (CVE-2026-8090)
Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2,
Firefox 150.0.2, Thunderbird ESR 140.10.2 and Thunderbird 150.0.2.
(CVE-2026-8092)
Another issue in the WebRTC component. (CVE-2026-8094)
                

References

SRPMS

9/core