{"id":"MGASA-2026-0345","summary":"Updated nspr, nss, & firefox packages fix security vulnerabilities","details":"Site isolation issue in the Graphics: CanvasWebGL component.\n(CVE-2026-74934)\nPrivilege escalation in the DOM: Networking component. (CVE-2026-74935)\nUse-after-free in the JavaScript: WebAssembly component.\n(CVE-2026-74936)\nUse-after-free in the JavaScript: GC component. (CVE-2026-74937)\nMitigation bypass in the JavaScript: GC component. (CVE-2026-74938)\nPrivilege escalation in the DOM: Navigation component. (CVE-2026-74939)\nUse-after-free in the Graphics: Text component. (CVE-2026-74940)\nPrivilege escalation in the Graphics: CanvasWebGL component.\n(CVE-2026-74941)\nPrivilege escalation in the Remote Settings Client component.\n(CVE-2026-74942)\nUse-after-free in the Graphics: ImageLib component. (CVE-2026-74943)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-74944)\nInformation disclosure in the Graphics: Text component. (CVE-2026-74945)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-74946)\nPrivilege escalation due to invalid pointer in the Graphics component.\n(CVE-2026-74947)\nInformation disclosure in the Graphics component. (CVE-2026-74948)\nPrivilege escalation in the Downloads API component. (CVE-2026-74950)\nPrivilege escalation in the Networking: Cookies component.\n(CVE-2026-74953)\nInformation disclosure due to side-channel in the Storage: Cache API\ncomponent. (CVE-2026-74954)\nPrivilege escalation in the Request Handling component. (CVE-2026-74955)\nSame-origin policy bypass in the DOM: Service Workers component.\n(CVE-2026-74956)\nMitigation bypass in the Safe Browsing component. (CVE-2026-74957)\nInformation disclosure in the WebRTC component. (CVE-2026-74958)\nMitigation bypass in the Storage: Cache API component. (CVE-2026-74959)\nSite isolation issue in the WebExtensions component. (CVE-2026-74960)\nSide-channel in the Web Audio component. (CVE-2026-74961)\nSite isolation issue in the Networking: Cookies component.\n(CVE-2026-74962)\nSame-origin policy bypass in the Networking: Cookies component.\n(CVE-2026-74963)\nInteger overflow in the Graphics component. (CVE-2026-74964)\nPrivilege escalation in the Shell Integration component.\n(CVE-2026-74965)\nInformation disclosure in the Form Autofill component. (CVE-2026-74966)\nSame-origin policy bypass in the Audio/Video: Playback component.\n(CVE-2026-74967)\nSite isolation issue in the Graphics: WebRender component.\n(CVE-2026-74968)\nUse-after-free in the Layout: Text and Fonts component. (CVE-2026-74969)\nSite isolation issue in the Graphics component. (CVE-2026-74970)\nInformation disclosure in the DOM: UI Events & Focus Handling component.\n(CVE-2026-74971)\nInformation disclosure in the DOM: Push Subscriptions component.\n(CVE-2026-74972)\nUse-after-free in the Graphics: Canvas2D component. (CVE-2026-74949)\nRace condition, use-after-free in the Graphics component.\n(CVE-2026-74973)\nSame-origin policy bypass in the Graphics: ImageLib component.\n(CVE-2026-74974)\nJIT miscompilation in the JavaScript Engine: JIT component.\n(CVE-2026-74976)\nInteger overflow in the Graphics component. (CVE-2026-74977)\nClickjacking issue in the Widget component. (CVE-2026-74978)\nMitigation bypass in the Add-ons Manager component. (CVE-2026-74979)\nSite isolation issue in the Audio/Video: Web Codecs component.\n(CVE-2026-74981)\nDenial-of-service in the Widget component. (CVE-2026-74982)\nMitigation bypass in the Data Loss Prevention component.\n(CVE-2026-74983)\nRace condition in the JavaScript Engine component. (CVE-2026-74984)\nPrivilege escalation in the Enterprise Policies component.\n(CVE-2026-74985)\nSite isolation issue in the CSS Parsing and Computation component.\n(CVE-2026-74986)\nInternally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and\nFirefox 154. (CVE-2026-74987)\nInternally found bugs fixed in Firefox ESR 153.1 and Firefox 154.\n(CVE-2026-74988)\nInternally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and\nFirefox 154. (CVE-2026-74990)\n","modified":"2026-08-31T16:41:23.597140869Z","published":"2026-08-31T16:22:02Z","upstream":["CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74937","CVE-2026-74938","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74947","CVE-2026-74948","CVE-2026-74949","CVE-2026-74950","CVE-2026-74953","CVE-2026-74954","CVE-2026-74955","CVE-2026-74956","CVE-2026-74957","CVE-2026-74958","CVE-2026-74959","CVE-2026-74960","CVE-2026-74961","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74966","CVE-2026-74967","CVE-2026-74968","CVE-2026-74969","CVE-2026-74970","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74977","CVE-2026-74978","CVE-2026-74979","CVE-2026-74981","CVE-2026-74982","CVE-2026-74983","CVE-2026-74984","CVE-2026-74985","CVE-2026-74986","CVE-2026-74987","CVE-2026-74988","CVE-2026-74990"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0345.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36123"},{"type":"WEB","url":"https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_127.html"},{"type":"WEB","url":"https://github.com/mozilla/nspr/releases/tag/NSPR_4_40_RTM"},{"type":"WEB","url":"https://www.firefox.com/en-US/firefox/140.14.0/releasenotes/"},{"type":"WEB","url":"https://www.firefox.com/en-US/firefox/153.1.0/releasenotes/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/"}],"affected":[{"package":{"name":"nspr","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/nspr?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.40.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0345.json"}},{"package":{"name":"nss","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.127.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0345.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.1.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0345.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.1.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0345.json"}},{"package":{"name":"nspr","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/nspr?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.40.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0345.json"}},{"package":{"name":"nss","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.127.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0345.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0345.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0345.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}