{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0387",
  "published": "2026-09-09T18:01:33Z",
  "modified": "2026-09-09T16:32:19Z",
  "summary": "Updated firefox & nss packages fix security vulnerabilities",
  "details": "Sandbox escape in the Remote Settings Client component. (CVE-2026-75874)\nPrivilege escalation in the DOM: Workers component. (CVE-2026-16365)\nUse-after-free in the JavaScript: GC component. (CVE-2026-84118)\nSandbox escape due to use-after-free in the DOM: Navigation component.\n(CVE-2026-84119)\nUse-after-free in the Audio/Video component. (CVE-2026-84120)\nSandbox escape due to use-after-free in the DOM: Security component.\n(CVE-2026-84121)\nUse-after-free in the Audio/Video component. (CVE-2026-84122)\nPrivilege escalation due to use-after-free in the Graphics: WebGPU\ncomponent. (CVE-2026-84123)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-84124)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-84125)\nPrivilege escalation in the DOM: Navigation component. (CVE-2026-16371)\nPrivilege escalation in the Application Update component.\n(CVE-2026-74952)\nSite isolation issue in the DOM: Navigation component. (CVE-2026-84129)\nInformation disclosure in the Graphics: WebGPU component.\n(CVE-2026-84130)\nPrivilege escalation due to invalid pointer in the Graphics component.\n(CVE-2026-84131)\nInformation disclosure in the Networking: HTTP component.\n(CVE-2026-84132)\nSite isolation issue in the DOM: Push Subscriptions component.\n(CVE-2026-84133)\nOther issue in the Profile Backup component. (CVE-2026-84134)\nOther issue in the DOM: Navigation component. (CVE-2026-84136)\nSpoofing issue in the DOM: Core & HTML component. (CVE-2026-84137)\nClickjacking issue in the DOM: Events component. (CVE-2026-84139)\nSite isolation issue in the DOM: Navigation component. (CVE-2026-84140)\nInteger overflow in the Graphics: ImageLib component. (CVE-2026-84141)\nInternally found bugs fixed in Firefox 155, Firefox ESR 153.2 and\nFirefox ESR 140.15. (CVE-2026-84143)\nInternally found bugs fixed in Firefox 155 and Firefox ESR 153.2.\n(CVE-2026-84144)\nInternally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox\nESR 140.15 and Firefox ESR 115.40. (CVE-2026-84145)\n",
  "upstream": [
    "CVE-2026-75874",
    "CVE-2026-16365",
    "CVE-2026-84118",
    "CVE-2026-84119",
    "CVE-2026-84120",
    "CVE-2026-84121",
    "CVE-2026-84122",
    "CVE-2026-84123",
    "CVE-2026-84124",
    "CVE-2026-84125",
    "CVE-2026-74952",
    "CVE-2026-84129",
    "CVE-2026-16371",
    "CVE-2026-84130",
    "CVE-2026-84131",
    "CVE-2026-84132",
    "CVE-2026-84133",
    "CVE-2026-84134",
    "CVE-2026-84136",
    "CVE-2026-84137",
    "CVE-2026-84139",
    "CVE-2026-84140",
    "CVE-2026-84141",
    "CVE-2026-84143",
    "CVE-2026-84144",
    "CVE-2026-84145"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0387.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36235"
    },
    {
      "type": "WEB",
      "url": "https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_128.html"
    },
    {
      "type": "WEB",
      "url": "https://www.firefox.com/en-US/firefox/140.15.0/releasenotes/"
    },
    {
      "type": "WEB",
      "url": "https://www.firefox.com/en-US/firefox/153.2.0/releasenotes/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "firefox-l10n",
        "purl": "pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.2.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "firefox",
        "purl": "pkg:rpm/mageia/firefox?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.2.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "nss",
        "purl": "pkg:rpm/mageia/nss?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.128.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "firefox-l10n",
        "purl": "pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.15.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "firefox",
        "purl": "pkg:rpm/mageia/firefox?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.15.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "nss",
        "purl": "pkg:rpm/mageia/nss?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.128.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
