This update for MozillaFirefox fixes the following issue
Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071):
- CVE-2026-12289: Privilege escalation in the Graphics: WebRender component.
- CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12291: Use-after-free in the Networking: HTTP component.
- CVE-2026-12292: Incorrect boundary conditions in the Web Audio component.
- CVE-2026-12294: Sandbox escape in the DOM: Workers component.
- CVE-2026-12295: Sandbox escape in the DOM: Navigation component.
- CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component.
- CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component.
- CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12.
- CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component.
- CVE-2026-12302: Mitigation bypass in the DOM: Security component.
- CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies...
Read the Full Advisory- openSUSE Leap 16.0:
MozillaFirefox-140.12.0-160000.1.1
MozillaFirefox-branding-upstream-140.12.0-160000.1.1
MozillaFirefox-devel-140.12.0-160000.1.1
MozillaFirefox-translations-common-140.12.0-160000.1.1
MozillaFirefox-translations-other-140.12.0-160000.1.1
* bsc#1268071
References:
* https://www.suse.com/security/cve/CVE-2026-12289.html
* https://www.suse.com/security/cve/CVE-2026-12290.html
* https://www.suse.com/security/cve/CVE-2026-12291.html
* https://www.suse.com/security/cve/CVE-2026-12292.html
* https://www.suse.com/security/cve/CVE-2026-12294.html
* https://www.suse.com/security/cve/CVE-2026-12295.html
* https://www.suse.com/security/cve/CVE-2026-12296.html
* https://www.suse.com/security/cve/CVE-2026-12297.html
* https://www.suse.com/security/cve/CVE-2026-12298.html
* https://www.suse.com/security/cve/CVE-2026-12299.html
* https://www.suse.com/security/cve/CVE-2026-12302.html
* https://www.suse.com/security/cve/CVE-2026-12304.html
* https://www.suse.com/security/cve/CVE-2026-12305.html
* https://www.suse.com/security/cve/CVE-2026-12306.html
* https://www.suse.com/security/cve/CVE-2026-12307.html
* https://www.suse.com/security/cve/CVE-2026-12308.html
* https://www.suse.com/security/cve/CVE-2026-12309.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.