Advisories ยป MGASA-2026-0441

Updated nss & firefox packages fix security vulnerabilities

Publication date: 23 Sep 2026
Modification date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078

Description

Use-after-free in the Audio/Video: Web Codecs component.
(CVE-2026-92005)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92006)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92007)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92008)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92009)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92010)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92011)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92012)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92013)
Privilege escalation due to incorrect boundary conditions in the
Graphics component. (CVE-2026-92014)
Privilege escalation in the WebExtensions component. (CVE-2026-92015)
Use-after-free in the Disability Access APIs component. (CVE-2026-92016)
Privilege escalation in the DOM: Service Workers component.
(CVE-2026-92017)
Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018)
Mitigation bypass in the Remote Settings Client component.
(CVE-2026-92019)
Privilege escalation due to incorrect boundary conditions in the
Graphics: WebRender component. (CVE-2026-92020)
Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021)
Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022)
Use-after-free in the XML component. (CVE-2026-92023)
Use-after-free in the SVG component. (CVE-2026-92024)
Use-after-free in the DOM: Navigation component. (CVE-2026-92025)
Use-after-free in the Networking component. (CVE-2026-92026)
Use-after-free in the DOM: Streams component. (CVE-2026-92027)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028)
Use-after-free in the SVG component. (CVE-2026-92029)
Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component.
(CVE-2026-92030)
Information disclosure in the Graphics: ImageLib component.
(CVE-2026-92031)
Sandbox escape due to invalid pointer in the Graphics component.
(CVE-2026-92032)
Mitigation bypass in the Remote Settings Client component.
(CVE-2026-92038)
Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039)
Mitigation bypass in the DOM: Networking component. (CVE-2026-92041)
Race condition in the DOM: Content Processes component. (CVE-2026-92042)
Privilege escalation due to incorrect boundary conditions in the
Audio/Video component. (CVE-2026-92043)
Information disclosure in the Networking: HTTP component.
(CVE-2026-92044)
Sandbox escape due to incorrect boundary conditions in the WebRTC
component. (CVE-2026-92045)
Use-after-free in the Graphics component. (CVE-2026-92046)
Privilege escalation in the Crash Reporting component. (CVE-2026-92047)
Privilege escalation due to uninitialized memory in the Graphics:
CanvasWebGL component. (CVE-2026-92052)
Privilege escalation in the Graphics: CanvasWebGL component.
(CVE-2026-92053)
Privilege escalation in the Memory component. (CVE-2026-92054)
Privilege escalation in the DevTools component. (CVE-2026-92055)
Use-after-free in the Graphics: Text component. (CVE-2026-92056)
Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057)
Use-after-free in the Graphics component. (CVE-2026-92058)
Incorrect boundary conditions in the DOM: Editor component.
(CVE-2026-92059)
Use-after-free in the Internationalization component. (CVE-2026-92060)
Privilege escalation in the Session Restore component. (CVE-2026-92062)
Use-after-free in the Widget: Gtk component. (CVE-2026-92067)
Site isolation issue in the Reader Mode component. (CVE-2026-92068)
Spoofing issue in the DOM: Navigation component. (CVE-2026-92069)
Information disclosure in the Networking component. (CVE-2026-92070)
Incorrect boundary conditions in the Safe Browsing component.
(CVE-2026-92072)
Privilege escalation in the Enterprise Policies component.
(CVE-2026-92073)
Mitigation bypass in the Popup Blocker component. (CVE-2026-92074)
Mitigation bypass in the Networking component. (CVE-2026-92075)
Incorrect boundary conditions in the Networking component.
(CVE-2026-92076)
Denial-of-service in the SVG component. (CVE-2026-92077)
Denial-of-service in the Security component. (CVE-2026-92078)
                

References

SRPMS

10/core

9/core