[Git][security-tracker-team/security-tracker][master] Track fixed version for firefox-esr issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 2 06:16:45 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
71a3487d by Salvatore Bonaccorso at 2026-09-02T07:15:15+02:00
Track fixed version for firefox-esr issues
Note that CVE-2026-16371 version got bumped to 140.15.0 based one. It
was originally addressed in 140.13.0, but might have incomplete (no
details in the mfsa2026-84 on why it is fixed again).
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -525,7 +525,7 @@ CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher
TODO: check
CVE-2026-84145 (Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firef ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84145
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84145
CVE-2026-84144 (Internally found bugs present in Firefox 154 and Firefox ESR 153.1. So ...)
@@ -533,7 +533,7 @@ CVE-2026-84144 (Internally found bugs present in Firefox 154 and Firefox ESR 153
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
CVE-2026-84143 (Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Fi ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84143
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84143
CVE-2026-84142 (Internally found bugs present in Firefox 154. Some of these bugs showe ...)
@@ -571,7 +571,7 @@ CVE-2026-84132 (Information disclosure in the Networking: HTTP component. This v
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84132
CVE-2026-84131 (Privilege escalation due to invalid pointer in the Graphics component. ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84131
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84131
CVE-2026-84130 (Information disclosure in the Graphics: WebGPU component. This vulnera ...)
@@ -594,7 +594,7 @@ CVE-2026-84125 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84125
CVE-2026-84124 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84124
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84124
CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: WebGPU com ...)
@@ -602,22 +602,22 @@ CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: WebG
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84123
CVE-2026-84122 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84122
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security component. T ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84121
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
CVE-2026-84120 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84120
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
CVE-2026-84119 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84119
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84119
CVE-2026-84118 (Use-after-free in the JavaScript: GC component. This vulnerability was ...)
@@ -15335,7 +15335,7 @@ CVE-2026-75890
REJECTED
CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
- firefox 154.0-1
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-75874
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-75874
CVE-2026-75872 (HTML Injection in the public subscription form in maalfer MailerUp bef ...)
@@ -48304,7 +48304,7 @@ CVE-2026-16372 (Privilege escalation in the DOM: Content Processes component. Th
CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
{DSA-6418-1 DSA-6394-1 DLA-4727-1 DLA-4695-1}
- firefox 153.0-1
- - firefox-esr 140.13.0esr-1
+ - firefox-esr 140.15.0esr-1
- thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
@@ -48377,7 +48377,7 @@ CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This vuln
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16366
CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This vulnerability ...)
- firefox 153.0-1
- - firefox-esr <unfixed>
+ - firefox-esr 140.15.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16365
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-16365
CVE-2026-16364 (Incorrect boundary conditions in the Audio/Video: Playback component. ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71a3487d1c4fb8bed3e06a281c38adb5f5635058
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/71a3487d1c4fb8bed3e06a281c38adb5f5635058
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/079594ac/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list