{"id":"MGASA-2026-0441","summary":"Updated nss & firefox packages fix security vulnerabilities","details":"Use-after-free in the Audio/Video: Web Codecs component.\n(CVE-2026-92005)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92006)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92007)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92008)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92009)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92010)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92011)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92012)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92013)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics component. (CVE-2026-92014)\nPrivilege escalation in the WebExtensions component. (CVE-2026-92015)\nUse-after-free in the Disability Access APIs component. (CVE-2026-92016)\nPrivilege escalation in the DOM: Service Workers component.\n(CVE-2026-92017)\nSandbox escape in the DOM: Core & HTML component. (CVE-2026-92018)\nMitigation bypass in the Remote Settings Client component.\n(CVE-2026-92019)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: WebRender component. (CVE-2026-92020)\nUse-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021)\nUse-after-free in the DOM: HTML Parser component. (CVE-2026-92022)\nUse-after-free in the XML component. (CVE-2026-92023)\nUse-after-free in the SVG component. (CVE-2026-92024)\nUse-after-free in the DOM: Navigation component. (CVE-2026-92025)\nUse-after-free in the Networking component. (CVE-2026-92026)\nUse-after-free in the DOM: Streams component. (CVE-2026-92027)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-92028)\nUse-after-free in the SVG component. (CVE-2026-92029)\nMitigation bypass in the DOM: Copy & Paste and Drag & Drop component.\n(CVE-2026-92030)\nInformation disclosure in the Graphics: ImageLib component.\n(CVE-2026-92031)\nSandbox escape due to invalid pointer in the Graphics component.\n(CVE-2026-92032)\nMitigation bypass in the Remote Settings Client component.\n(CVE-2026-92038)\nMitigation bypass in the DOM: Notifications component. (CVE-2026-92039)\nMitigation bypass in the DOM: Networking component. (CVE-2026-92041)\nRace condition in the DOM: Content Processes component. (CVE-2026-92042)\nPrivilege escalation due to incorrect boundary conditions in the\nAudio/Video component. (CVE-2026-92043)\nInformation disclosure in the Networking: HTTP component.\n(CVE-2026-92044)\nSandbox escape due to incorrect boundary conditions in the WebRTC\ncomponent. (CVE-2026-92045)\nUse-after-free in the Graphics component. (CVE-2026-92046)\nPrivilege escalation in the Crash Reporting component. (CVE-2026-92047)\nPrivilege escalation due to uninitialized memory in the Graphics:\nCanvasWebGL component. (CVE-2026-92052)\nPrivilege escalation in the Graphics: CanvasWebGL component.\n(CVE-2026-92053)\nPrivilege escalation in the Memory component. (CVE-2026-92054)\nPrivilege escalation in the DevTools component. (CVE-2026-92055)\nUse-after-free in the Graphics: Text component. (CVE-2026-92056)\nMitigation bypass in the Enterprise Policies component. (CVE-2026-92057)\nUse-after-free in the Graphics component. (CVE-2026-92058)\nIncorrect boundary conditions in the DOM: Editor component.\n(CVE-2026-92059)\nUse-after-free in the Internationalization component. (CVE-2026-92060)\nPrivilege escalation in the Session Restore component. (CVE-2026-92062)\nUse-after-free in the Widget: Gtk component. (CVE-2026-92067)\nSite isolation issue in the Reader Mode component. (CVE-2026-92068)\nSpoofing issue in the DOM: Navigation component. (CVE-2026-92069)\nInformation disclosure in the Networking component. (CVE-2026-92070)\nIncorrect boundary conditions in the Safe Browsing component.\n(CVE-2026-92072)\nPrivilege escalation in the Enterprise Policies component.\n(CVE-2026-92073)\nMitigation bypass in the Popup Blocker component. (CVE-2026-92074)\nMitigation bypass in the Networking component. (CVE-2026-92075)\nIncorrect boundary conditions in the Networking component.\n(CVE-2026-92076)\nDenial-of-service in the SVG component. (CVE-2026-92077)\nDenial-of-service in the Security component. (CVE-2026-92078)\n","modified":"2026-09-23T17:00:04.975469640Z","published":"2026-09-23T16:56:55Z","upstream":["CVE-2026-92005","CVE-2026-92006","CVE-2026-92007","CVE-2026-92008","CVE-2026-92009","CVE-2026-92010","CVE-2026-92011","CVE-2026-92012","CVE-2026-92013","CVE-2026-92014","CVE-2026-92015","CVE-2026-92016","CVE-2026-92017","CVE-2026-92018","CVE-2026-92019","CVE-2026-92020","CVE-2026-92021","CVE-2026-92022","CVE-2026-92023","CVE-2026-92024","CVE-2026-92025","CVE-2026-92026","CVE-2026-92027","CVE-2026-92028","CVE-2026-92029","CVE-2026-92030","CVE-2026-92031","CVE-2026-92032","CVE-2026-92038","CVE-2026-92039","CVE-2026-92041","CVE-2026-92042","CVE-2026-92043","CVE-2026-92044","CVE-2026-92045","CVE-2026-92046","CVE-2026-92047","CVE-2026-92052","CVE-2026-92053","CVE-2026-92054","CVE-2026-92055","CVE-2026-92056","CVE-2026-92057","CVE-2026-92058","CVE-2026-92059","CVE-2026-92060","CVE-2026-92062","CVE-2026-92064","CVE-2026-92067","CVE-2026-92068","CVE-2026-92069","CVE-2026-92070","CVE-2026-92072","CVE-2026-92073","CVE-2026-92074","CVE-2026-92075","CVE-2026-92076","CVE-2026-92077","CVE-2026-92078"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0441.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36317"},{"type":"WEB","url":"https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_129.html"},{"type":"WEB","url":"https://www.firefox.com/en-US/firefox/140.16.0/releasenotes/"},{"type":"WEB","url":"https://www.firefox.com/en-US/firefox/153.3.0/releasenotes/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/"}],"affected":[{"package":{"name":"firefox-l10n","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0441.json"}},{"package":{"name":"nss","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.129.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0441.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0441.json"}},{"package":{"name":"firefox-l10n","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/firefox-l10n?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.16.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0441.json"}},{"package":{"name":"nss","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.129.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0441.json"}},{"package":{"name":"firefox","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/firefox?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.16.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0441.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}