Description:
LZ4 compression library issue. (CVE-2025-62813)
libexpat before 2.7.5 allows a NULL pointer dereference with empty
external parameter entity content. (CVE-2026-32776)
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
(CVE-2026-32777)
libexpat before 2.7.5 allows a NULL pointer dereference in the function
setContext on retry after an earlier ouf-of-memory condition.
(CVE-2026-32778)
Use-after-free in the DOM: Networking component. (CVE-2026-8090)
Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2,
Firefox 150.0.2, Thunderbird ESR 140.10.2 and Thunderbird 150.0.2.
(CVE-2026-8092)
Another issue in the WebRTC component. (CVE-2026-8094)
- https://bugs.mageia.org/show_bug.cgi?id=35508
- https://www.firefox.com/en-US/firefox/140.10.2/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/140.10.2esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-41/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-44/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-62813
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32776
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32777
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32778
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8090
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8092
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8094
- 9/core/firefox-140.10.2-1.mga9
- 9/core/firefox-l10n-140.10.2-1.mga9
- 9/core/thunderbird-140.10.2-1.mga9
- 9/core/thunderbird-l10n-140.10.2-1.mga9
Get the latest Linux and open source security news straight to your inbox.