{"id":"MGASA-2026-0387","summary":"Updated firefox & nss packages fix security vulnerabilities","details":"Sandbox escape in the Remote Settings Client component. (CVE-2026-75874)\nPrivilege escalation in the DOM: Workers component. (CVE-2026-16365)\nUse-after-free in the JavaScript: GC component. (CVE-2026-84118)\nSandbox escape due to use-after-free in the DOM: Navigation component.\n(CVE-2026-84119)\nUse-after-free in the Audio/Video component. (CVE-2026-84120)\nSandbox escape due to use-after-free in the DOM: Security component.\n(CVE-2026-84121)\nUse-after-free in the Audio/Video component. (CVE-2026-84122)\nPrivilege escalation due to use-after-free in the Graphics: WebGPU\ncomponent. (CVE-2026-84123)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-84124)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-84125)\nPrivilege escalation in the DOM: Navigation component. (CVE-2026-16371)\nPrivilege escalation in the Application Update component.\n(CVE-2026-74952)\nSite isolation issue in the DOM: Navigation component. (CVE-2026-84129)\nInformation disclosure in the Graphics: WebGPU component.\n(CVE-2026-84130)\nPrivilege escalation due to invalid pointer in the Graphics component.\n(CVE-2026-84131)\nInformation disclosure in the Networking: HTTP component.\n(CVE-2026-84132)\nSite isolation issue in the DOM: Push Subscriptions component.\n(CVE-2026-84133)\nOther issue in the Profile Backup component. (CVE-2026-84134)\nOther issue in the DOM: Navigation component. (CVE-2026-84136)\nSpoofing issue in the DOM: Core & HTML component. (CVE-2026-84137)\nClickjacking issue in the DOM: Events component. (CVE-2026-84139)\nSite isolation issue in the DOM: Navigation component. (CVE-2026-84140)\nInteger overflow in the Graphics: ImageLib component. (CVE-2026-84141)\nInternally found bugs fixed in Firefox 155, Firefox ESR 153.2 and\nFirefox ESR 140.15. (CVE-2026-84143)\nInternally found bugs fixed in Firefox 155 and Firefox ESR 153.2.\n(CVE-2026-84144)\nInternally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox\nESR 140.15 and Firefox ESR 115.40. (CVE-2026-84145)\n","modified":"2026-09-09T18:27:33.396333031Z","published":"2026-09-09T18:01:33Z","upstream":["CVE-2026-16365","CVE-2026-16371","CVE-2026-74952","CVE-2026-75874","CVE-2026-84118","CVE-2026-84119","CVE-2026-84120","CVE-2026-84121","CVE-2026-84122","CVE-2026-84123","CVE-2026-84124","CVE-2026-84125","CVE-2026-84129","CVE-2026-84130","CVE-2026-84131","CVE-2026-84132","CVE-2026-84133","CVE-2026-84134","CVE-2026-84136","CVE-2026-84137","CVE-2026-84139","CVE-2026-84140","CVE-2026-84141","CVE-2026-84143","CVE-2026-84144","CVE-2026-84145"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0387.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36235"},{"type":"WEB","url":"https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_128.html"},{"type":"WEB","url":"https://www.firefox.com/en-US/firefox/140.15.0/releasenotes/"},{"type":"WEB","url":"https://www.firefox.com/en-US/firefox/153.2.0/releasenotes/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/"}],"affected":[{"package":{"name":"firefox-l10n","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.2.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0387.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.2.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0387.json"}},{"package":{"name":"nss","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.128.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0387.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.15.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0387.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.15.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0387.json"}},{"package":{"name":"nss","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.128.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0387.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}