Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE: MozillaFirefox Important Privilege Escalation Issues 2026:20014-1

opensuse
Calendar Grey January 13, 2026
Dist Opensuse Esm H88
Fixed 10 vulnerabilities in MozillaFirefox for openSUSE, including important issues like privilege escalation and JIT miscompilation.
An update that solves 10 vulnerabilities and has one bug fix can now be installed.

Description

This update for MozillaFirefox fixes the following issues:

Changes in MozillaFirefox:

Firefox Extended Support Release 140.6.0 ESR was released:

* Fixed: Various security fixes.

MFSA 2025-94 (bsc#1254551):

* CVE-2025-14321: Use-after-free in the WebRTC: Signaling component

* CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component

* CVE-2025-14323: Privilege escalation in the DOM: Notifications component

* CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT component

* CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component

* CVE-2025-14328: Privilege escalation in the Netmonitor component

* CVE-2025-14329: Privilege escalation in the Netmonitor component

* CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT component

* CVE-2025-14331: Same-origin policy bypass in the Request Handling component

* CVE-2025-14333: Memory safety bugs fixed in Firefox ESR 140.6,...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

MozillaFirefox-140.6.0-160000.1.1

MozillaFirefox-branding-upstream-140.6.0-160000.1.1

MozillaFirefox-devel-140.6.0-160000.1.1

MozillaFirefox-translations-common-140.6.0-160000.1.1

MozillaFirefox-translations-other-140.6.0-160000.1.1

References

* bsc#1254551

References:

* https://www.suse.com/security/cve/CVE-2025-14321.html

* https://www.suse.com/security/cve/CVE-2025-14322.html

* https://www.suse.com/security/cve/CVE-2025-14323.html

* https://www.suse.com/security/cve/CVE-2025-14324.html

* https://www.suse.com/security/cve/CVE-2025-14325.html

* https://www.suse.com/security/cve/CVE-2025-14328.html

* https://www.suse.com/security/cve/CVE-2025-14329.html

* https://www.suse.com/security/cve/CVE-2025-14330.html

* https://www.suse.com/security/cve/CVE-2025-14331.html

* https://www.suse.com/security/cve/CVE-2025-14333.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20014-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here