Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

SUSE: 2021:14826-1 Important: MozillaFirefox Memory Safety Update

suse
Calendar Grey October 18, 2021
Scroller Suse
SUSE has released a security update addressing vulnerabilities in Thunderbird and cargo-fmt, enhancing overall reliability and protection.
An update that fixes 20 vulnerabilities, contains one feature is now available

Summary

This update for MozillaFirefox, rust-cbindgen fixes the following issues: MozillaFirefox was updated to Extended Support Release 91.2.0 ESR * Fixed: Various stability, functionality, and security fixes MFSA 2021-45 (bsc#1191332) * CVE-2021-38496: Use-after-free in MessageTask * CVE-2021-38497: Validation message could have been overlaid on another origin * CVE-2021-38498: Use-after-free of nsLanguageAtomService object * CVE-2021-32810: Data race in crossbeam-deque * CVE-2021-38500: Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and Firefox ESR 91.2 * CVE-2021-38501: Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2 - Fixed crash in FIPS mode (bsc#1190710) Firefox Extended Support Release 91.1.0 ESR * Fixed: Various stability, functionality, and security fixes

References

#1188891 #1189547 #1190269 #1190274 #1190710

#1191332 SLE-18626

Cross- CVE-2021-29980 CVE-2021-29981 CVE-2021-29982

CVE-2021-29983 CVE-2021-29984 CVE-2021-29985

CVE-2021-29986 CVE-2021-29987 CVE-2021-29988

CVE-2021-29989 CVE-2021-29990 CVE-2021-29991

CVE-2021-32810 CVE-2021-38492 CVE-2021-38495

CVE-2021-38496 CVE-2021-38497 CVE-2021-38498

CVE-2021-38500 CVE-2021-38501

CVSS scores:

CVE-2021-29980 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-29984 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-29985 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVE-2021-29986 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-29988 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:14826-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.