Updated firefox & nss packages fix security vulnerabilities
Publication date: 09 Sep 2026Modification date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-75874 , CVE-2026-16365 , CVE-2026-84118 , CVE-2026-84119 , CVE-2026-84120 , CVE-2026-84121 , CVE-2026-84122 , CVE-2026-84123 , CVE-2026-84124 , CVE-2026-84125 , CVE-2026-74952 , CVE-2026-84129 , CVE-2026-16371 , CVE-2026-84130 , CVE-2026-84131 , CVE-2026-84132 , CVE-2026-84133 , CVE-2026-84134 , CVE-2026-84136 , CVE-2026-84137 , CVE-2026-84139 , CVE-2026-84140 , CVE-2026-84141 , CVE-2026-84143 , CVE-2026-84144 , CVE-2026-84145
Description
Sandbox escape in the Remote Settings Client component. (CVE-2026-75874)
Privilege escalation in the DOM: Workers component. (CVE-2026-16365)
Use-after-free in the JavaScript: GC component. (CVE-2026-84118)
Sandbox escape due to use-after-free in the DOM: Navigation component.
(CVE-2026-84119)
Use-after-free in the Audio/Video component. (CVE-2026-84120)
Sandbox escape due to use-after-free in the DOM: Security component.
(CVE-2026-84121)
Use-after-free in the Audio/Video component. (CVE-2026-84122)
Privilege escalation due to use-after-free in the Graphics: WebGPU
component. (CVE-2026-84123)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-84124)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-84125)
Privilege escalation in the DOM: Navigation component. (CVE-2026-16371)
Privilege escalation in the Application Update component.
(CVE-2026-74952)
Site isolation issue in the DOM: Navigation component. (CVE-2026-84129)
Information disclosure in the Graphics: WebGPU component.
(CVE-2026-84130)
Privilege escalation due to invalid pointer in the Graphics component.
(CVE-2026-84131)
Information disclosure in the Networking: HTTP component.
(CVE-2026-84132)
Site isolation issue in the DOM: Push Subscriptions component.
(CVE-2026-84133)
Other issue in the Profile Backup component. (CVE-2026-84134)
Other issue in the DOM: Navigation component. (CVE-2026-84136)
Spoofing issue in the DOM: Core & HTML component. (CVE-2026-84137)
Clickjacking issue in the DOM: Events component. (CVE-2026-84139)
Site isolation issue in the DOM: Navigation component. (CVE-2026-84140)
Integer overflow in the Graphics: ImageLib component. (CVE-2026-84141)
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and
Firefox ESR 140.15. (CVE-2026-84143)
Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2.
(CVE-2026-84144)
Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox
ESR 140.15 and Firefox ESR 115.40. (CVE-2026-84145)
References
- https://bugs.mageia.org/show_bug.cgi?id=36235
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_128.html
- https://www.firefox.com/en-US/firefox/140.15.0/releasenotes/
- https://www.firefox.com/en-US/firefox/153.2.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/
- https://www.cve.org/CVERecord?id=CVE-2026-75874
- https://www.cve.org/CVERecord?id=CVE-2026-16365
- https://www.cve.org/CVERecord?id=CVE-2026-84118
- https://www.cve.org/CVERecord?id=CVE-2026-84119
- https://www.cve.org/CVERecord?id=CVE-2026-84120
- https://www.cve.org/CVERecord?id=CVE-2026-84121
- https://www.cve.org/CVERecord?id=CVE-2026-84122
- https://www.cve.org/CVERecord?id=CVE-2026-84123
- https://www.cve.org/CVERecord?id=CVE-2026-84124
- https://www.cve.org/CVERecord?id=CVE-2026-84125
- https://www.cve.org/CVERecord?id=CVE-2026-74952
- https://www.cve.org/CVERecord?id=CVE-2026-84129
- https://www.cve.org/CVERecord?id=CVE-2026-16371
- https://www.cve.org/CVERecord?id=CVE-2026-84130
- https://www.cve.org/CVERecord?id=CVE-2026-84131
- https://www.cve.org/CVERecord?id=CVE-2026-84132
- https://www.cve.org/CVERecord?id=CVE-2026-84133
- https://www.cve.org/CVERecord?id=CVE-2026-84134
- https://www.cve.org/CVERecord?id=CVE-2026-84136
- https://www.cve.org/CVERecord?id=CVE-2026-84137
- https://www.cve.org/CVERecord?id=CVE-2026-84139
- https://www.cve.org/CVERecord?id=CVE-2026-84140
- https://www.cve.org/CVERecord?id=CVE-2026-84141
- https://www.cve.org/CVERecord?id=CVE-2026-84143
- https://www.cve.org/CVERecord?id=CVE-2026-84144
- https://www.cve.org/CVERecord?id=CVE-2026-84145
SRPMS
10/core
- firefox-l10n-153.2.0-1.mga10
- firefox-153.2.0-1.mga10
- nss-3.128.0-1.mga10
9/core
- firefox-l10n-140.15.0-1.mga9
- firefox-140.15.0-1.mga9
- nss-3.128.0-1.mga9