[Git][security-tracker-team/security-tracker][master] 2 commits: Add tracking for firefox-esr (via mfsa2026-84)

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 1 17:03:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8bf9eb27 by Salvatore Bonaccorso at 2026-09-01T18:02:32+02:00
Add tracking for firefox-esr (via mfsa2026-84)

- - - - -
55d31b75 by Salvatore Bonaccorso at 2026-09-01T18:02:33+02:00
Add firefox-esr to dsa-needed list

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,12 +1,16 @@
 CVE-2026-84145
 	- firefox <unfixed>
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84145
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84145
 CVE-2026-84144
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
 CVE-2026-84143
 	- firefox <unfixed>
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84143
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84143
 CVE-2026-84142
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84142
@@ -42,7 +46,9 @@ CVE-2026-84132
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84132
 CVE-2026-84131
 	- firefox <unfixed>
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84131
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84131
 CVE-2026-84130
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84130
@@ -63,22 +69,32 @@ CVE-2026-84125
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84125
 CVE-2026-84124
 	- firefox <unfixed>
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84124
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84124
 CVE-2026-84123
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84123
 CVE-2026-84122
 	- firefox <unfixed>
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84122
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
 CVE-2026-84121
 	- firefox <unfixed>
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84121
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
 CVE-2026-84120
 	- firefox <unfixed>
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84120
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
 CVE-2026-84119
 	- firefox <unfixed>
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84119
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84119
 CVE-2026-84118
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84118
@@ -14794,7 +14810,9 @@ CVE-2026-75890
 	REJECTED
 CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
 	- firefox 154.0-1
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-75874
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-75874
 CVE-2026-75872 (HTML Injection in the public subscription form in maalfer MailerUp bef ...)
 	NOT-FOR-US: maalfer MailerUp
 CVE-2026-75859 (CodeWhale versions before 0.8.64 fail to validate file paths in the pr ...)
@@ -47763,6 +47781,7 @@ CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vuln
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16371
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-16371
 CVE-2026-16370 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
 	- firefox 153.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
@@ -47830,7 +47849,9 @@ CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This vuln
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16366
 CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This vulnerability ...)
 	- firefox 153.0-1
+	- firefox-esr <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16365
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-16365
 CVE-2026-16364 (Incorrect boundary conditions in the Audio/Video: Playback component.  ...)
 	- firefox 153.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16364


=====================================
data/dsa-needed.txt
=====================================
@@ -40,6 +40,8 @@ firebird3.0
 --
 firebird4.0
 --
+firefox-esr (jmm)
+--
 fort-validator (jmm)
   Maintainer preparing update
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/635491ca1e9e9b9b3209516c15f0f9482d500cad...55d31b75edf889216aedb5e8339e085f1bbd0f4e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/635491ca1e9e9b9b3209516c15f0f9482d500cad...55d31b75edf889216aedb5e8339e085f1bbd0f4e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/a4a792fd/attachment.htm>


More information about the debian-security-tracker-commits mailing list