[Git][security-tracker-team/security-tracker][master] Adjust version for firefox-esr via unstable upload for mfsa2026-76

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 19 11:45:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ffedccb4 by Salvatore Bonaccorso at 2026-08-19T12:43:50+02:00
Adjust version for firefox-esr via unstable upload for mfsa2026-76

Bump version to 140.14.0.

Apparently 140.14.0esr-1 as well did not make it to the archive (maybe a
transient error on uploading), so mark only the one entering unstable as
the fixed version (140.14.0esr-2).

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2340,7 +2340,7 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet len
 	TODO: check, Red Hat bugzilla entry (only source) contains no information
 CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74990
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74990
@@ -2353,7 +2353,7 @@ CVE-2026-74988 (Internally found bugs present in Thunderbird ESR 153.0 and Thund
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
 CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74987
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74987
@@ -2369,7 +2369,7 @@ CVE-2026-74984 (Race condition in the JavaScript Engine component. This vulnerab
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
 CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74983
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74983
@@ -2394,7 +2394,7 @@ CVE-2026-74977 (Integer overflow in the Graphics component. This vulnerability w
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
 CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74976
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74976
@@ -2404,28 +2404,28 @@ CVE-2026-74975 (Spoofing issue in the Downloads component in Firefox for Android
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
 CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. This vu ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74974
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
 CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This vulnera ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74973
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
 CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component. This  ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74972
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
 CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling componen ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74971
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74971
@@ -2435,7 +2435,7 @@ CVE-2026-74970 (Site isolation issue in the Graphics component. This vulnerabili
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
 CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This vulnerabi ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74969
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74969
@@ -2445,7 +2445,7 @@ CVE-2026-74968 (Site isolation issue in the Graphics: WebRender component. This
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
 CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback component. This ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74967
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74967
@@ -2455,28 +2455,28 @@ CVE-2026-74966 (Information disclosure in the Form Autofill component. This vuln
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
 CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vulnerab ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74965
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
 CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability was fix ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74964
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
 CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component. This v ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74963
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
 CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. This vulner ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74962
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74962
@@ -2486,14 +2486,14 @@ CVE-2026-74961 (Side-channel in the Web Audio component. This vulnerability was
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
 CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulnerabilit ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74960
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
 CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This vulnerabil ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74959
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74959
@@ -2503,7 +2503,7 @@ CVE-2026-74958 (Information disclosure in the WebRTC component. This vulnerabili
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
 CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This vulnerability w ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74957
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74957
@@ -2519,7 +2519,7 @@ CVE-2026-74954 (Information disclosure due to side-channel in the Storage: Cache
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
 CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. This vulner ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74953
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74953
@@ -2535,14 +2535,14 @@ CVE-2026-74950 (Privilege escalation in the Downloads API component. This vulner
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
 CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canvas2D c ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74949
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
 CVE-2026-74948 (Information disclosure in the Graphics component. This vulnerability w ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74948
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74948
@@ -2552,56 +2552,56 @@ CVE-2026-74947 (Privilege escalation due to invalid pointer in the Graphics comp
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
 CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74946
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
 CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vulnerabi ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74945
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
 CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74944
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
 CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnerability ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74943
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
 CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. This vul ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74942
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
 CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74941
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
 CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74940
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
 CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74939
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74939
@@ -2614,21 +2614,21 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC component. This vulnerabili
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
 CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74936
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
 CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vulnerabil ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74935
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
 CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. This vuln ...)
 	- firefox 154.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.14.0esr-2
 	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74934
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74934



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ffedccb4ff5f0805aceb75f0f312574225a0bc62

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ffedccb4ff5f0805aceb75f0f312574225a0bc62
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/61b7e21f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list