Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE MozillaFirefox Important Memory Safety Sandbox Escape 2026-20789-1

opensuse
Calendar Grey May 25, 2026
Dist Opensuse Esm H88
This openSUSE security update addresses 20 issues in Firefox ensuring safer browsing.
An update that solves 20 vulnerabilities and has one bug fix can now be installed.

Description

This update for MozillaFirefox fixes the following issues

- Update to Firefox Extended Support Release 140.11.0 ESR MFSA 2026-48 (bsc#1265212).

MFSA 2026-48:

- CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component.

- CVE-2026-8391: Other issue in the JavaScript Engine component.

- CVE-2026-8401: Sandbox escape in the Profile Backup component.

- CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component.

- CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component.

- CVE-2026-8949: Integer overflow in the Widget: Win32 component.

- CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component.

- CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component.

- CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component.

- CVE-2026-8955: Privilege escalation in the DOM: Workers component.

- CVE-2026-8956: Integer overflow in the Networking:...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

MozillaFirefox-140.11.0-160000.1.1

MozillaFirefox-branding-upstream-140.11.0-160000.1.1

MozillaFirefox-devel-140.11.0-160000.1.1

MozillaFirefox-translations-common-140.11.0-160000.1.1

MozillaFirefox-translations-other-140.11.0-160000.1.1

References

* bsc#1265212

References:

* https://www.suse.com/security/cve/CVE-2026-8388.html

* https://www.suse.com/security/cve/CVE-2026-8391.html

* https://www.suse.com/security/cve/CVE-2026-8401.html

* https://www.suse.com/security/cve/CVE-2026-8946.html

* https://www.suse.com/security/cve/CVE-2026-8947.html

* https://www.suse.com/security/cve/CVE-2026-8949.html

* https://www.suse.com/security/cve/CVE-2026-8950.html

* https://www.suse.com/security/cve/CVE-2026-8953.html

* https://www.suse.com/security/cve/CVE-2026-8954.html

* https://www.suse.com/security/cve/CVE-2026-8955.html

* https://www.suse.com/security/cve/CVE-2026-8956.html

* https://www.suse.com/security/cve/CVE-2026-8957.html

* https://www.suse.com/security/cve/CVE-2026-8958.html

* https://www.suse.com/security/cve/CVE-2026-8959.html

* https://www.suse.com/security/cve/CVE-2026-8961.html

* https://www.suse.com/security/cve/CVE-2026-8962.html

* https://www.suse.com/security/cve/CVE-2026-8968.html

* https://www.suse.com/security/cve/CVE-2026-8970.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20789-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here