{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0441",
  "published": "2026-09-23T16:56:55Z",
  "modified": "2026-09-23T15:45:05Z",
  "summary": "Updated nss & firefox packages fix security vulnerabilities",
  "details": "Use-after-free in the Audio/Video: Web Codecs component.\n(CVE-2026-92005)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92006)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92007)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92008)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92009)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92010)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92011)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92012)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92013)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics component. (CVE-2026-92014)\nPrivilege escalation in the WebExtensions component. (CVE-2026-92015)\nUse-after-free in the Disability Access APIs component. (CVE-2026-92016)\nPrivilege escalation in the DOM: Service Workers component.\n(CVE-2026-92017)\nSandbox escape in the DOM: Core & HTML component. (CVE-2026-92018)\nMitigation bypass in the Remote Settings Client component.\n(CVE-2026-92019)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: WebRender component. (CVE-2026-92020)\nUse-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021)\nUse-after-free in the DOM: HTML Parser component. (CVE-2026-92022)\nUse-after-free in the XML component. (CVE-2026-92023)\nUse-after-free in the SVG component. (CVE-2026-92024)\nUse-after-free in the DOM: Navigation component. (CVE-2026-92025)\nUse-after-free in the Networking component. (CVE-2026-92026)\nUse-after-free in the DOM: Streams component. (CVE-2026-92027)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-92028)\nUse-after-free in the SVG component. (CVE-2026-92029)\nMitigation bypass in the DOM: Copy & Paste and Drag & Drop component.\n(CVE-2026-92030)\nInformation disclosure in the Graphics: ImageLib component.\n(CVE-2026-92031)\nSandbox escape due to invalid pointer in the Graphics component.\n(CVE-2026-92032)\nMitigation bypass in the Remote Settings Client component.\n(CVE-2026-92038)\nMitigation bypass in the DOM: Notifications component. (CVE-2026-92039)\nMitigation bypass in the DOM: Networking component. (CVE-2026-92041)\nRace condition in the DOM: Content Processes component. (CVE-2026-92042)\nPrivilege escalation due to incorrect boundary conditions in the\nAudio/Video component. (CVE-2026-92043)\nInformation disclosure in the Networking: HTTP component.\n(CVE-2026-92044)\nSandbox escape due to incorrect boundary conditions in the WebRTC\ncomponent. (CVE-2026-92045)\nUse-after-free in the Graphics component. (CVE-2026-92046)\nPrivilege escalation in the Crash Reporting component. (CVE-2026-92047)\nPrivilege escalation due to uninitialized memory in the Graphics:\nCanvasWebGL component. (CVE-2026-92052)\nPrivilege escalation in the Graphics: CanvasWebGL component.\n(CVE-2026-92053)\nPrivilege escalation in the Memory component. (CVE-2026-92054)\nPrivilege escalation in the DevTools component. (CVE-2026-92055)\nUse-after-free in the Graphics: Text component. (CVE-2026-92056)\nMitigation bypass in the Enterprise Policies component. (CVE-2026-92057)\nUse-after-free in the Graphics component. (CVE-2026-92058)\nIncorrect boundary conditions in the DOM: Editor component.\n(CVE-2026-92059)\nUse-after-free in the Internationalization component. (CVE-2026-92060)\nPrivilege escalation in the Session Restore component. (CVE-2026-92062)\nUse-after-free in the Widget: Gtk component. (CVE-2026-92067)\nSite isolation issue in the Reader Mode component. (CVE-2026-92068)\nSpoofing issue in the DOM: Navigation component. (CVE-2026-92069)\nInformation disclosure in the Networking component. (CVE-2026-92070)\nIncorrect boundary conditions in the Safe Browsing component.\n(CVE-2026-92072)\nPrivilege escalation in the Enterprise Policies component.\n(CVE-2026-92073)\nMitigation bypass in the Popup Blocker component. (CVE-2026-92074)\nMitigation bypass in the Networking component. (CVE-2026-92075)\nIncorrect boundary conditions in the Networking component.\n(CVE-2026-92076)\nDenial-of-service in the SVG component. (CVE-2026-92077)\nDenial-of-service in the Security component. (CVE-2026-92078)\n",
  "upstream": [
    "CVE-2026-92005",
    "CVE-2026-92006",
    "CVE-2026-92007",
    "CVE-2026-92008",
    "CVE-2026-92009",
    "CVE-2026-92010",
    "CVE-2026-92011",
    "CVE-2026-92012",
    "CVE-2026-92013",
    "CVE-2026-92014",
    "CVE-2026-92015",
    "CVE-2026-92016",
    "CVE-2026-92017",
    "CVE-2026-92018",
    "CVE-2026-92019",
    "CVE-2026-92020",
    "CVE-2026-92021",
    "CVE-2026-92022",
    "CVE-2026-92023",
    "CVE-2026-92024",
    "CVE-2026-92025",
    "CVE-2026-92026",
    "CVE-2026-92027",
    "CVE-2026-92028",
    "CVE-2026-92029",
    "CVE-2026-92030",
    "CVE-2026-92031",
    "CVE-2026-92032",
    "CVE-2026-92038",
    "CVE-2026-92039",
    "CVE-2026-92041",
    "CVE-2026-92042",
    "CVE-2026-92043",
    "CVE-2026-92044",
    "CVE-2026-92045",
    "CVE-2026-92046",
    "CVE-2026-92047",
    "CVE-2026-92052",
    "CVE-2026-92053",
    "CVE-2026-92054",
    "CVE-2026-92055",
    "CVE-2026-92056",
    "CVE-2026-92057",
    "CVE-2026-92058",
    "CVE-2026-92059",
    "CVE-2026-92060",
    "CVE-2026-92062",
    "CVE-2026-92064",
    "CVE-2026-92067",
    "CVE-2026-92068",
    "CVE-2026-92069",
    "CVE-2026-92070",
    "CVE-2026-92072",
    "CVE-2026-92073",
    "CVE-2026-92074",
    "CVE-2026-92075",
    "CVE-2026-92076",
    "CVE-2026-92077",
    "CVE-2026-92078"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0441.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36317"
    },
    {
      "type": "WEB",
      "url": "https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_129.html"
    },
    {
      "type": "WEB",
      "url": "https://www.firefox.com/en-US/firefox/140.16.0/releasenotes/"
    },
    {
      "type": "WEB",
      "url": "https://www.firefox.com/en-US/firefox/153.3.0/releasenotes/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "firefox-l10n",
        "purl": "pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.3.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "nss",
        "purl": "pkg:rpm/mageia/nss?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.129.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "firefox",
        "purl": "pkg:rpm/mageia/firefox?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.3.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "firefox-l10n",
        "purl": "pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.16.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "nss",
        "purl": "pkg:rpm/mageia/nss?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.129.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "firefox",
        "purl": "pkg:rpm/mageia/firefox?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.16.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
