Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

openSUSE MozillaFirefox Important Vulnerability Fixes 2026-21043-1

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
Update for MozillaFirefox on openSUSE addresses 29 issues including essential security fixes and enhancements.
An update that solves 29 vulnerabilities and has one bug fix can now be installed.

Description

This update for MozillaFirefox fixes the following issue

Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071):

- CVE-2026-12289: Privilege escalation in the Graphics: WebRender component.

- CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12.

- CVE-2026-12291: Use-after-free in the Networking: HTTP component.

- CVE-2026-12292: Incorrect boundary conditions in the Web Audio component.

- CVE-2026-12294: Sandbox escape in the DOM: Workers component.

- CVE-2026-12295: Sandbox escape in the DOM: Navigation component.

- CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component.

- CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component.

- CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12.

- CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component.

- CVE-2026-12302: Mitigation bypass in the DOM: Security component.

- CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

MozillaFirefox-140.12.0-160000.1.1

MozillaFirefox-branding-upstream-140.12.0-160000.1.1

MozillaFirefox-devel-140.12.0-160000.1.1

MozillaFirefox-translations-common-140.12.0-160000.1.1

MozillaFirefox-translations-other-140.12.0-160000.1.1

References

* bsc#1268071

References:

* https://www.suse.com/security/cve/CVE-2026-12289.html

* https://www.suse.com/security/cve/CVE-2026-12290.html

* https://www.suse.com/security/cve/CVE-2026-12291.html

* https://www.suse.com/security/cve/CVE-2026-12292.html

* https://www.suse.com/security/cve/CVE-2026-12294.html

* https://www.suse.com/security/cve/CVE-2026-12295.html

* https://www.suse.com/security/cve/CVE-2026-12296.html

* https://www.suse.com/security/cve/CVE-2026-12297.html

* https://www.suse.com/security/cve/CVE-2026-12298.html

* https://www.suse.com/security/cve/CVE-2026-12299.html

* https://www.suse.com/security/cve/CVE-2026-12302.html

* https://www.suse.com/security/cve/CVE-2026-12304.html

* https://www.suse.com/security/cve/CVE-2026-12305.html

* https://www.suse.com/security/cve/CVE-2026-12306.html

* https://www.suse.com/security/cve/CVE-2026-12307.html

* https://www.suse.com/security/cve/CVE-2026-12308.html

* https://www.suse.com/security/cve/CVE-2026-12309.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21043-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here