Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

openSUSE Leap 16.0 mozjs115 Important Denial of Service CVE-2026-32776

opensuse
Calendar Grey May 21, 2026
Scroller Opensuse
Explore the latest openSUSE security advisory for mozjs115 fixing critical issues. Stay protected with the recommended patches.
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

Description

This update for mozjs115 fixes the following issues:

Changes in mozjs115:

- CVE-2026-32776: Fixed a NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259728)

- CVE-2026-32777: Fixed a denial of service due to infinite loop in DTD content parsing (bsc#1259713)

- CVE-2026-32778: Fixed a NULL pointer dereference in 'setContext' on retry after an out-of-memory condition (bsc#1259731)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-261=1

Patch

Package List

- openSUSE Leap 16.0:

libmozjs-115-0-115.15.0-bp160.2.1

mozjs115-115.15.0-bp160.2.1

mozjs115-devel-115.15.0-bp160.2.1

References

* bsc#1259713

* bsc#1259728

* bsc#1259731

References:

* https://www.suse.com/security/cve/CVE-2026-32776.html

* https://www.suse.com/security/cve/CVE-2026-32777.html

* https://www.suse.com/security/cve/CVE-2026-32778.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20769-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.