{"id":"openSUSE-SU-2026:20439-1","summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following issues:\n\nUpdate to Firefox 140.9.0 ESR (MFSA 2026-22, bsc#1260083):\n\n  - CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component\n  - CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component\n  - CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component\n  - CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component\n  - CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component\n  - CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component\n  - CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component\n  - CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component\n  - CVE-2026-4692: Sandbox escape in the Responsive Design Mode component\n  - CVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component\n  - CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component\n  - CVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component\n  - CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component\n  - CVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component\n  - CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component\n  - CVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component\n  - CVE-2026-4700: Mitigation bypass in the Networking: HTTP component\n  - CVE-2026-4701: Use-after-free in the JavaScript Engine component\n  - CVE-2026-4702: JIT miscompilation in the JavaScript Engine component\n  - CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component\n  - CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component\n  - CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component\n  - CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component\n  - CVE-2026-4708: Incorrect boundary conditions in the Graphics component\n  - CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component\n  - CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component\n  - CVE-2026-4711: Use-after-free in the Widget: Cocoa component\n  - CVE-2026-4712: Information disclosure in the Widget: Cocoa component\n  - CVE-2026-4713: Incorrect boundary conditions in the Graphics component\n  - CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component\n  - CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component\n  - CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component\n  - CVE-2026-4717: Privilege escalation in the Netmonitor component\n  - CVE-2025-59375: Denial-of-service in the XML component\n  - CVE-2026-4718: Undefined behavior in the WebRTC: Signaling component\n  - CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component\n  - CVE-2026-4720: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and\n    Thunderbird 149\n  - CVE-2026-4721: Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9,\n    Firefox 149 and Thunderbird 149\n","modified":"2026-04-03T17:25:02.625305Z","published":"2026-03-27T12:32:55Z","related":["CVE-2025-59375","CVE-2026-4684","CVE-2026-4685","CVE-2026-4686","CVE-2026-4687","CVE-2026-4688","CVE-2026-4689","CVE-2026-4690","CVE-2026-4691","CVE-2026-4692","CVE-2026-4693","CVE-2026-4694","CVE-2026-4695","CVE-2026-4696","CVE-2026-4697","CVE-2026-4698","CVE-2026-4699","CVE-2026-4700","CVE-2026-4701","CVE-2026-4702","CVE-2026-4704","CVE-2026-4705","CVE-2026-4706","CVE-2026-4707","CVE-2026-4708","CVE-2026-4709","CVE-2026-4710","CVE-2026-4711","CVE-2026-4712","CVE-2026-4713","CVE-2026-4714","CVE-2026-4715","CVE-2026-4716","CVE-2026-4717","CVE-2026-4718","CVE-2026-4719","CVE-2026-4720","CVE-2026-4721"],"upstream":["CVE-2025-59375","CVE-2026-4684","CVE-2026-4685","CVE-2026-4686","CVE-2026-4687","CVE-2026-4688","CVE-2026-4689","CVE-2026-4690","CVE-2026-4691","CVE-2026-4692","CVE-2026-4693","CVE-2026-4694","CVE-2026-4695","CVE-2026-4696","CVE-2026-4697","CVE-2026-4698","CVE-2026-4699","CVE-2026-4700","CVE-2026-4701","CVE-2026-4702","CVE-2026-4704","CVE-2026-4705","CVE-2026-4706","CVE-2026-4707","CVE-2026-4708","CVE-2026-4709","CVE-2026-4710","CVE-2026-4711","CVE-2026-4712","CVE-2026-4713","CVE-2026-4714","CVE-2026-4715","CVE-2026-4716","CVE-2026-4717","CVE-2026-4718","CVE-2026-4719","CVE-2026-4720","CVE-2026-4721"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4686"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4687"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4688"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4689"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4690"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4692"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4693"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4696"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4697"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4698"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4699"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4701"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4702"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4704"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4706"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4707"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4709"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4710"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4711"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4712"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4713"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4714"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4715"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4716"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4717"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4718"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4719"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4720"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4721"}],"affected":[{"package":{"name":"MozillaFirefox","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.9.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"140.9.0-160000.1.1","MozillaFirefox-branding-upstream":"140.9.0-160000.1.1","MozillaFirefox-devel":"140.9.0-160000.1.1","MozillaFirefox-translations-common":"140.9.0-160000.1.1","MozillaFirefox-translations-other":"140.9.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20439-1.json"}}],"schema_version":"1.7.5"}