This update for MozillaFirefox fixes the following issues:
Update to Firefox 140.9.0 ESR (MFSA 2026-22, bsc#1260083):
* CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender
component
* CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D
component
* CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D
component
* CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the
Telemetry component
* CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access
APIs component
* CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer
overflow in the XPCOM component
* CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer
overflow in the XPCOM component
* CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component
* CVE-2026-4692: Sandbox escape in the Responsive Design Mode component
* CVE-2026-4693:...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2026-1126=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1126=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1126=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1126=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1126=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1126=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1126=1
* SUSE Linux...
Read the Full Advisory* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* MozillaFirefox-debuginfo-140.9.0-150200.152.225.1
* MozillaFirefox-translations-other-140.9.0-150200.152.225.1
* MozillaFirefox-branding-upstream-140.9.0-150200.152.225.1
* MozillaFirefox-140.9.0-150200.152.225.1
* MozillaFirefox-translations-common-140.9.0-150200.152.225.1
* MozillaFirefox-debugsource-140.9.0-150200.152.225.1
* openSUSE Leap 15.6 (noarch)
* MozillaFirefox-devel-140.9.0-150200.152.225.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* MozillaFirefox-debuginfo-140.9.0-150200.152.225.1
* MozillaFirefox-translations-other-140.9.0-150200.152.225.1
* MozillaFirefox-140.9.0-150200.152.225.1
* MozillaFirefox-translations-common-140.9.0-150200.152.225.1
* MozillaFirefox-debugsource-140.9.0-150200.152.225.1
* Desktop Applications Module 15-SP7 (noarch)
* MozillaFirefox-devel-140.9.0-150200.152.225.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
*...
Read the Full Advisory* bsc#1260083
## References:
* https://www.suse.com/security/cve/CVE-2025-59375.html
* https://www.suse.com/security/cve/CVE-2026-4684.html
* https://www.suse.com/security/cve/CVE-2026-4685.html
* https://www.suse.com/security/cve/CVE-2026-4686.html
* https://www.suse.com/security/cve/CVE-2026-4687.html
* https://www.suse.com/security/cve/CVE-2026-4688.html
* https://www.suse.com/security/cve/CVE-2026-4689.html
* https://www.suse.com/security/cve/CVE-2026-4690.html
* https://www.suse.com/security/cve/CVE-2026-4691.html
* https://www.suse.com/security/cve/CVE-2026-4692.html
* https://www.suse.com/security/cve/CVE-2026-4693.html
* https://www.suse.com/security/cve/CVE-2026-4694.html
* https://www.suse.com/security/cve/CVE-2026-4695.html
* https://www.suse.com/security/cve/CVE-2026-4696.html
* https://www.suse.com/security/cve/CVE-2026-4697.html
* https://www.suse.com/security/cve/CVE-2026-4698.html
* https://www.suse.com/security/cve/CVE-2026-4699.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.