Updated nspr, nss, & firefox packages fix security vulnerabilities
Publication date: 31 Aug 2026Modification date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990
Description
Site isolation issue in the Graphics: CanvasWebGL component.
(CVE-2026-74934)
Privilege escalation in the DOM: Networking component. (CVE-2026-74935)
Use-after-free in the JavaScript: WebAssembly component.
(CVE-2026-74936)
Use-after-free in the JavaScript: GC component. (CVE-2026-74937)
Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938)
Privilege escalation in the DOM: Navigation component. (CVE-2026-74939)
Use-after-free in the Graphics: Text component. (CVE-2026-74940)
Privilege escalation in the Graphics: CanvasWebGL component.
(CVE-2026-74941)
Privilege escalation in the Remote Settings Client component.
(CVE-2026-74942)
Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944)
Information disclosure in the Graphics: Text component. (CVE-2026-74945)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-74946)
Privilege escalation due to invalid pointer in the Graphics component.
(CVE-2026-74947)
Information disclosure in the Graphics component. (CVE-2026-74948)
Privilege escalation in the Downloads API component. (CVE-2026-74950)
Privilege escalation in the Networking: Cookies component.
(CVE-2026-74953)
Information disclosure due to side-channel in the Storage: Cache API
component. (CVE-2026-74954)
Privilege escalation in the Request Handling component. (CVE-2026-74955)
Same-origin policy bypass in the DOM: Service Workers component.
(CVE-2026-74956)
Mitigation bypass in the Safe Browsing component. (CVE-2026-74957)
Information disclosure in the WebRTC component. (CVE-2026-74958)
Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959)
Site isolation issue in the WebExtensions component. (CVE-2026-74960)
Side-channel in the Web Audio component. (CVE-2026-74961)
Site isolation issue in the Networking: Cookies component.
(CVE-2026-74962)
Same-origin policy bypass in the Networking: Cookies component.
(CVE-2026-74963)
Integer overflow in the Graphics component. (CVE-2026-74964)
Privilege escalation in the Shell Integration component.
(CVE-2026-74965)
Information disclosure in the Form Autofill component. (CVE-2026-74966)
Same-origin policy bypass in the Audio/Video: Playback component.
(CVE-2026-74967)
Site isolation issue in the Graphics: WebRender component.
(CVE-2026-74968)
Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969)
Site isolation issue in the Graphics component. (CVE-2026-74970)
Information disclosure in the DOM: UI Events & Focus Handling component.
(CVE-2026-74971)
Information disclosure in the DOM: Push Subscriptions component.
(CVE-2026-74972)
Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949)
Race condition, use-after-free in the Graphics component.
(CVE-2026-74973)
Same-origin policy bypass in the Graphics: ImageLib component.
(CVE-2026-74974)
JIT miscompilation in the JavaScript Engine: JIT component.
(CVE-2026-74976)
Integer overflow in the Graphics component. (CVE-2026-74977)
Clickjacking issue in the Widget component. (CVE-2026-74978)
Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979)
Site isolation issue in the Audio/Video: Web Codecs component.
(CVE-2026-74981)
Denial-of-service in the Widget component. (CVE-2026-74982)
Mitigation bypass in the Data Loss Prevention component.
(CVE-2026-74983)
Race condition in the JavaScript Engine component. (CVE-2026-74984)
Privilege escalation in the Enterprise Policies component.
(CVE-2026-74985)
Site isolation issue in the CSS Parsing and Computation component.
(CVE-2026-74986)
Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and
Firefox 154. (CVE-2026-74987)
Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154.
(CVE-2026-74988)
Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and
Firefox 154. (CVE-2026-74990)
References
- https://bugs.mageia.org/show_bug.cgi?id=36123
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_127.html
- https://github.com/mozilla/nspr/releases/tag/NSPR_4_40_RTM
- https://www.firefox.com/en-US/firefox/140.14.0/releasenotes/
- https://www.firefox.com/en-US/firefox/153.1.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/
- https://www.cve.org/CVERecord?id=CVE-2026-74934
- https://www.cve.org/CVERecord?id=CVE-2026-74935
- https://www.cve.org/CVERecord?id=CVE-2026-74936
- https://www.cve.org/CVERecord?id=CVE-2026-74937
- https://www.cve.org/CVERecord?id=CVE-2026-74938
- https://www.cve.org/CVERecord?id=CVE-2026-74939
- https://www.cve.org/CVERecord?id=CVE-2026-74940
- https://www.cve.org/CVERecord?id=CVE-2026-74941
- https://www.cve.org/CVERecord?id=CVE-2026-74942
- https://www.cve.org/CVERecord?id=CVE-2026-74943
- https://www.cve.org/CVERecord?id=CVE-2026-74944
- https://www.cve.org/CVERecord?id=CVE-2026-74945
- https://www.cve.org/CVERecord?id=CVE-2026-74946
- https://www.cve.org/CVERecord?id=CVE-2026-74947
- https://www.cve.org/CVERecord?id=CVE-2026-74948
- https://www.cve.org/CVERecord?id=CVE-2026-74950
- https://www.cve.org/CVERecord?id=CVE-2026-74953
- https://www.cve.org/CVERecord?id=CVE-2026-74954
- https://www.cve.org/CVERecord?id=CVE-2026-74955
- https://www.cve.org/CVERecord?id=CVE-2026-74956
- https://www.cve.org/CVERecord?id=CVE-2026-74957
- https://www.cve.org/CVERecord?id=CVE-2026-74958
- https://www.cve.org/CVERecord?id=CVE-2026-74959
- https://www.cve.org/CVERecord?id=CVE-2026-74960
- https://www.cve.org/CVERecord?id=CVE-2026-74961
- https://www.cve.org/CVERecord?id=CVE-2026-74962
- https://www.cve.org/CVERecord?id=CVE-2026-74963
- https://www.cve.org/CVERecord?id=CVE-2026-74964
- https://www.cve.org/CVERecord?id=CVE-2026-74965
- https://www.cve.org/CVERecord?id=CVE-2026-74966
- https://www.cve.org/CVERecord?id=CVE-2026-74967
- https://www.cve.org/CVERecord?id=CVE-2026-74968
- https://www.cve.org/CVERecord?id=CVE-2026-74969
- https://www.cve.org/CVERecord?id=CVE-2026-74970
- https://www.cve.org/CVERecord?id=CVE-2026-74971
- https://www.cve.org/CVERecord?id=CVE-2026-74972
- https://www.cve.org/CVERecord?id=CVE-2026-74949
- https://www.cve.org/CVERecord?id=CVE-2026-74973
- https://www.cve.org/CVERecord?id=CVE-2026-74974
- https://www.cve.org/CVERecord?id=CVE-2026-74976
- https://www.cve.org/CVERecord?id=CVE-2026-74977
- https://www.cve.org/CVERecord?id=CVE-2026-74978
- https://www.cve.org/CVERecord?id=CVE-2026-74979
- https://www.cve.org/CVERecord?id=CVE-2026-74981
- https://www.cve.org/CVERecord?id=CVE-2026-74982
- https://www.cve.org/CVERecord?id=CVE-2026-74983
- https://www.cve.org/CVERecord?id=CVE-2026-74984
- https://www.cve.org/CVERecord?id=CVE-2026-74985
- https://www.cve.org/CVERecord?id=CVE-2026-74986
- https://www.cve.org/CVERecord?id=CVE-2026-74987
- https://www.cve.org/CVERecord?id=CVE-2026-74988
- https://www.cve.org/CVERecord?id=CVE-2026-74990
SRPMS
10/core
- nspr-4.40.0-1.mga10
- nss-3.127.0-1.mga10
- firefox-153.1.0-1.mga10
- firefox-l10n-153.1.0-1.mga10
9/core
- nspr-4.40.0-1.mga9
- nss-3.127.0-1.mga9
- firefox-140.14.0-1.mga9
- firefox-l10n-140.14.0-1.mga9