## This update for MozillaFirefox fixes the following issues: Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12.
* bsc#1268071
Cross-
* CVE-2026-12289
* CVE-2026-12290
* CVE-2026-12291
* CVE-2026-12292
* CVE-2026-12294
* CVE-2026-12295
* CVE-2026-12296
* CVE-2026-12297
* CVE-2026-12298
* CVE-2026-12299
* CVE-2026-12302
* CVE-2026-12304
* CVE-2026-12305
* CVE-2026-12306
* CVE-2026-12307
* CVE-2026-12308
* CVE-2026-12309
* CVE-2026-12310
* CVE-2026-12311
* CVE-2026-12312
* CVE-2026-12313
* CVE-2026-12314
* CVE-2026-12315
* CVE-2026-12324
* CVE-2026-12325
* CVE-2026-12327
* CVE-2026-12328
* CVE-2026-12329
* CVE-2026-12330
CVSS scores:
* CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Get the latest Linux and open source security news straight to your inbox.