[Git][security-tracker-team/security-tracker][master] Track fixed version for firefox-esr issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 2 06:16:45 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
71a3487d by Salvatore Bonaccorso at 2026-09-02T07:15:15+02:00
Track fixed version for firefox-esr issues

Note that CVE-2026-16371 version got bumped to 140.15.0 based one. It
was originally addressed in 140.13.0, but might have incomplete (no
details in the mfsa2026-84 on why it is fixed again).

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -525,7 +525,7 @@ CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher
 	TODO: check
 CVE-2026-84145 (Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firef ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84145
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84145
 CVE-2026-84144 (Internally found bugs present in Firefox 154 and Firefox ESR 153.1. So ...)
@@ -533,7 +533,7 @@ CVE-2026-84144 (Internally found bugs present in Firefox 154 and Firefox ESR 153
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
 CVE-2026-84143 (Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Fi ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84143
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84143
 CVE-2026-84142 (Internally found bugs present in Firefox 154. Some of these bugs showe ...)
@@ -571,7 +571,7 @@ CVE-2026-84132 (Information disclosure in the Networking: HTTP component. This v
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84132
 CVE-2026-84131 (Privilege escalation due to invalid pointer in the Graphics component. ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84131
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84131
 CVE-2026-84130 (Information disclosure in the Graphics: WebGPU component. This vulnera ...)
@@ -594,7 +594,7 @@ CVE-2026-84125 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84125
 CVE-2026-84124 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84124
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84124
 CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: WebGPU com ...)
@@ -602,22 +602,22 @@ CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: WebG
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84123
 CVE-2026-84122 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84122
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
 CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security component. T ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84121
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
 CVE-2026-84120 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84120
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
 CVE-2026-84119 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84119
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84119
 CVE-2026-84118 (Use-after-free in the JavaScript: GC component. This vulnerability was ...)
@@ -15335,7 +15335,7 @@ CVE-2026-75890
 	REJECTED
 CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
 	- firefox 154.0-1
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-75874
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-75874
 CVE-2026-75872 (HTML Injection in the public subscription form in maalfer MailerUp bef ...)
@@ -48304,7 +48304,7 @@ CVE-2026-16372 (Privilege escalation in the DOM: Content Processes component. Th
 CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
 	{DSA-6418-1 DSA-6394-1 DLA-4727-1 DLA-4695-1}
 	- firefox 153.0-1
-	- firefox-esr 140.13.0esr-1
+	- firefox-esr 140.15.0esr-1
 	- thunderbird 1:140.13.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
@@ -48377,7 +48377,7 @@ CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This vuln
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16366
 CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This vulnerability ...)
 	- firefox 153.0-1
-	- firefox-esr <unfixed>
+	- firefox-esr 140.15.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16365
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-16365
 CVE-2026-16364 (Incorrect boundary conditions in the Audio/Video: Playback component.  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71a3487d1c4fb8bed3e06a281c38adb5f5635058

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71a3487d1c4fb8bed3e06a281c38adb5f5635058
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/079594ac/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list