Updated nss & firefox packages fix security vulnerabilities
Publication date: 23 Sep 2026Modification date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078
Description
Use-after-free in the Audio/Video: Web Codecs component.
(CVE-2026-92005)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92006)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92007)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92008)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92009)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92010)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92011)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92012)
Privilege escalation due to incorrect boundary conditions in the
Graphics: CanvasWebGL component. (CVE-2026-92013)
Privilege escalation due to incorrect boundary conditions in the
Graphics component. (CVE-2026-92014)
Privilege escalation in the WebExtensions component. (CVE-2026-92015)
Use-after-free in the Disability Access APIs component. (CVE-2026-92016)
Privilege escalation in the DOM: Service Workers component.
(CVE-2026-92017)
Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018)
Mitigation bypass in the Remote Settings Client component.
(CVE-2026-92019)
Privilege escalation due to incorrect boundary conditions in the
Graphics: WebRender component. (CVE-2026-92020)
Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021)
Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022)
Use-after-free in the XML component. (CVE-2026-92023)
Use-after-free in the SVG component. (CVE-2026-92024)
Use-after-free in the DOM: Navigation component. (CVE-2026-92025)
Use-after-free in the Networking component. (CVE-2026-92026)
Use-after-free in the DOM: Streams component. (CVE-2026-92027)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028)
Use-after-free in the SVG component. (CVE-2026-92029)
Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component.
(CVE-2026-92030)
Information disclosure in the Graphics: ImageLib component.
(CVE-2026-92031)
Sandbox escape due to invalid pointer in the Graphics component.
(CVE-2026-92032)
Mitigation bypass in the Remote Settings Client component.
(CVE-2026-92038)
Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039)
Mitigation bypass in the DOM: Networking component. (CVE-2026-92041)
Race condition in the DOM: Content Processes component. (CVE-2026-92042)
Privilege escalation due to incorrect boundary conditions in the
Audio/Video component. (CVE-2026-92043)
Information disclosure in the Networking: HTTP component.
(CVE-2026-92044)
Sandbox escape due to incorrect boundary conditions in the WebRTC
component. (CVE-2026-92045)
Use-after-free in the Graphics component. (CVE-2026-92046)
Privilege escalation in the Crash Reporting component. (CVE-2026-92047)
Privilege escalation due to uninitialized memory in the Graphics:
CanvasWebGL component. (CVE-2026-92052)
Privilege escalation in the Graphics: CanvasWebGL component.
(CVE-2026-92053)
Privilege escalation in the Memory component. (CVE-2026-92054)
Privilege escalation in the DevTools component. (CVE-2026-92055)
Use-after-free in the Graphics: Text component. (CVE-2026-92056)
Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057)
Use-after-free in the Graphics component. (CVE-2026-92058)
Incorrect boundary conditions in the DOM: Editor component.
(CVE-2026-92059)
Use-after-free in the Internationalization component. (CVE-2026-92060)
Privilege escalation in the Session Restore component. (CVE-2026-92062)
Use-after-free in the Widget: Gtk component. (CVE-2026-92067)
Site isolation issue in the Reader Mode component. (CVE-2026-92068)
Spoofing issue in the DOM: Navigation component. (CVE-2026-92069)
Information disclosure in the Networking component. (CVE-2026-92070)
Incorrect boundary conditions in the Safe Browsing component.
(CVE-2026-92072)
Privilege escalation in the Enterprise Policies component.
(CVE-2026-92073)
Mitigation bypass in the Popup Blocker component. (CVE-2026-92074)
Mitigation bypass in the Networking component. (CVE-2026-92075)
Incorrect boundary conditions in the Networking component.
(CVE-2026-92076)
Denial-of-service in the SVG component. (CVE-2026-92077)
Denial-of-service in the Security component. (CVE-2026-92078)
References
- https://bugs.mageia.org/show_bug.cgi?id=36317
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_129.html
- https://www.firefox.com/en-US/firefox/140.16.0/releasenotes/
- https://www.firefox.com/en-US/firefox/153.3.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/
- https://www.cve.org/CVERecord?id=CVE-2026-92005
- https://www.cve.org/CVERecord?id=CVE-2026-92006
- https://www.cve.org/CVERecord?id=CVE-2026-92007
- https://www.cve.org/CVERecord?id=CVE-2026-92008
- https://www.cve.org/CVERecord?id=CVE-2026-92009
- https://www.cve.org/CVERecord?id=CVE-2026-92010
- https://www.cve.org/CVERecord?id=CVE-2026-92011
- https://www.cve.org/CVERecord?id=CVE-2026-92012
- https://www.cve.org/CVERecord?id=CVE-2026-92013
- https://www.cve.org/CVERecord?id=CVE-2026-92014
- https://www.cve.org/CVERecord?id=CVE-2026-92015
- https://www.cve.org/CVERecord?id=CVE-2026-92016
- https://www.cve.org/CVERecord?id=CVE-2026-92017
- https://www.cve.org/CVERecord?id=CVE-2026-92018
- https://www.cve.org/CVERecord?id=CVE-2026-92019
- https://www.cve.org/CVERecord?id=CVE-2026-92020
- https://www.cve.org/CVERecord?id=CVE-2026-92021
- https://www.cve.org/CVERecord?id=CVE-2026-92022
- https://www.cve.org/CVERecord?id=CVE-2026-92023
- https://www.cve.org/CVERecord?id=CVE-2026-92024
- https://www.cve.org/CVERecord?id=CVE-2026-92025
- https://www.cve.org/CVERecord?id=CVE-2026-92026
- https://www.cve.org/CVERecord?id=CVE-2026-92027
- https://www.cve.org/CVERecord?id=CVE-2026-92028
- https://www.cve.org/CVERecord?id=CVE-2026-92029
- https://www.cve.org/CVERecord?id=CVE-2026-92030
- https://www.cve.org/CVERecord?id=CVE-2026-92031
- https://www.cve.org/CVERecord?id=CVE-2026-92032
- https://www.cve.org/CVERecord?id=CVE-2026-92038
- https://www.cve.org/CVERecord?id=CVE-2026-92039
- https://www.cve.org/CVERecord?id=CVE-2026-92041
- https://www.cve.org/CVERecord?id=CVE-2026-92042
- https://www.cve.org/CVERecord?id=CVE-2026-92043
- https://www.cve.org/CVERecord?id=CVE-2026-92044
- https://www.cve.org/CVERecord?id=CVE-2026-92045
- https://www.cve.org/CVERecord?id=CVE-2026-92046
- https://www.cve.org/CVERecord?id=CVE-2026-92047
- https://www.cve.org/CVERecord?id=CVE-2026-92052
- https://www.cve.org/CVERecord?id=CVE-2026-92053
- https://www.cve.org/CVERecord?id=CVE-2026-92054
- https://www.cve.org/CVERecord?id=CVE-2026-92055
- https://www.cve.org/CVERecord?id=CVE-2026-92056
- https://www.cve.org/CVERecord?id=CVE-2026-92057
- https://www.cve.org/CVERecord?id=CVE-2026-92058
- https://www.cve.org/CVERecord?id=CVE-2026-92059
- https://www.cve.org/CVERecord?id=CVE-2026-92060
- https://www.cve.org/CVERecord?id=CVE-2026-92062
- https://www.cve.org/CVERecord?id=CVE-2026-92064
- https://www.cve.org/CVERecord?id=CVE-2026-92067
- https://www.cve.org/CVERecord?id=CVE-2026-92068
- https://www.cve.org/CVERecord?id=CVE-2026-92069
- https://www.cve.org/CVERecord?id=CVE-2026-92070
- https://www.cve.org/CVERecord?id=CVE-2026-92072
- https://www.cve.org/CVERecord?id=CVE-2026-92073
- https://www.cve.org/CVERecord?id=CVE-2026-92074
- https://www.cve.org/CVERecord?id=CVE-2026-92075
- https://www.cve.org/CVERecord?id=CVE-2026-92076
- https://www.cve.org/CVERecord?id=CVE-2026-92077
- https://www.cve.org/CVERecord?id=CVE-2026-92078
SRPMS
10/core
- firefox-l10n-153.3.0-1.mga10
- nss-3.129.0-1.mga10
- firefox-153.3.0-1.mga10
9/core
- firefox-l10n-140.16.0-1.mga9
- nss-3.129.0-1.mga9
- firefox-140.16.0-1.mga9