Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package MozillaFirefox for openSUSE:Factory 
checked in at 2026-07-23 23:09:31
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/MozillaFirefox (Old)
 and      /work/SRC/openSUSE:Factory/.MozillaFirefox.new.2004 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "MozillaFirefox"

Thu Jul 23 23:09:31 2026 rev:496 rq:1367336 version:153.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/MozillaFirefox/MozillaFirefox.changes    
2026-07-20 10:00:13.945931969 +0200
+++ /work/SRC/openSUSE:Factory/.MozillaFirefox.new.2004/MozillaFirefox.changes  
2026-07-23 23:10:29.352596074 +0200
@@ -1,0 +2,180 @@
+Mon Jul 20 05:13:38 UTC 2026 - Wolfgang Rosenauer <[email protected]>
+
+- Mozilla Firefox 153.0
+  https://www.firefox.com/en-US/firefox/153.0/releasenotes/
+  MFSA 2026-68 (bsc#1271649)
+  * CVE-2026-16349 (bmo#2034682)
+    Same-origin policy bypass in the DOM: Navigation component
+  * CVE-2026-16350 (bmo#2042033)
+    Incorrect boundary conditions in the Audio/Video: cubeb component
+  * CVE-2026-16362 (bmo#2043188)
+    Use-after-free in the WebRTC: Audio/Video component
+  * CVE-2026-16351 (bmo#2045468)
+    Sandbox escape due to use-after-free in the DOM: Navigation component
+  * CVE-2026-16352 (bmo#2046416)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16363 (bmo#2047689)
+    JIT miscompilation in the JavaScript: WebAssembly component
+  * CVE-2026-16364 (bmo#2047802)
+    Incorrect boundary conditions in the Audio/Video: Playback component
+  * CVE-2026-16365 (bmo#2049149)
+    Privilege escalation in the DOM: Workers component
+  * CVE-2026-16366 (bmo#2049181)
+    Privilege escalation in the DOM: Navigation component
+  * CVE-2026-16353 (bmo#2049523)
+    Invalid pointer in the DOM: Bindings (WebIDL) component
+  * CVE-2026-16354 (bmo#2050626)
+    Information disclosure in the Graphics: ImageLib component
+  * CVE-2026-16367 (bmo#2050627)
+    Sandbox escape due to invalid pointer in the Disability
+    Access APIs component
+  * CVE-2026-16368 (bmo#2051015)
+    Incorrect boundary conditions in the JavaScript: WebAssembly component
+  * CVE-2026-16369 (bmo#2051854)
+    Integer overflow in the JavaScript: WebAssembly component
+  * CVE-2026-16355 (bmo#2052207)
+    JIT miscompilation in the JavaScript Engine: JIT component
+  * CVE-2026-16356 (bmo#2052562)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16357 (bmo#2053326)
+    Incorrect boundary conditions in the Graphics component
+  * CVE-2026-16370 (bmo#1996495)
+    Mitigation bypass in the DOM: Networking component
+  * CVE-2026-16371 (bmo#2008369)
+    Privilege escalation in the DOM: Navigation component
+  * CVE-2026-16372 (bmo#2013800)
+    Privilege escalation in the DOM: Content Processes component
+  * CVE-2026-16373 (bmo#2021964)
+    Information disclosure in the Privacy component in Firefox
+    for Android
+  * CVE-2026-16374 (bmo#2027519)
+    Information disclosure in the Framework component in DevTools
+  * CVE-2026-16375 (bmo#2032140)
+    Site isolation issue in the Networking: HTTP component
+  * CVE-2026-16376 (bmo#2035733)
+    Denial-of-service in the Graphics: WebGPU component
+  * CVE-2026-16377 (bmo#2037770)
+    Mitigation bypass in the PDF Viewer component
+  * CVE-2026-16378 (bmo#2038868)
+    Other issue in the DOM: Copy & Paste and Drag & Drop component
+  * CVE-2026-16379 (bmo#2039452)
+    Privilege escalation in the DOM: Content Processes component
+  * CVE-2026-16358 (bmo#2040119)
+    Site isolation issue in the Graphics: WebRender component
+  * CVE-2026-16380 (bmo#2040386)
+    Mitigation bypass in the Networking component
+  * CVE-2026-16381 (bmo#2041001)
+    Same-origin policy bypass in the Networking: DNS component
+  * CVE-2026-16382 (bmo#2041864)
+    Mitigation bypass in the DOM: Service Workers component
+  * CVE-2026-16383 (bmo#2041902)
+    Mitigation bypass in the DOM: Networking component
+  * CVE-2026-16384 (bmo#2041911)
+    Information disclosure due to uninitialized memory in the
+    Graphics: WebGPU component
+  * CVE-2026-16385 (bmo#2041912)
+    Information disclosure due to uninitialized memory in the
+    Graphics: WebGPU component
+  * CVE-2026-16386 (bmo#2041916)
+    Information disclosure due to uninitialized memory in the
+    Graphics: WebGPU component
+  * CVE-2026-16387 (bmo#2043200)
+    Site isolation issue in the Networking component
+  * CVE-2026-16388 (bmo#2043845)
+    Sandbox escape in the DOM: Networking component
+  * CVE-2026-16389 (bmo#2043887)
+    Incorrect boundary conditions, integer overflow in the
+    Libraries component in NSS
+  * CVE-2026-16390 (bmo#2044527)
+    Mitigation bypass in the Enterprise Policies component
+  * CVE-2026-16391 (bmo#2044536)
+    Information disclosure in the Storage: IndexedDB component
+  * CVE-2026-16392 (bmo#2044606)
+    JIT miscompilation in the JavaScript Engine: JIT component
+  * CVE-2026-16393 (bmo#2045410)
+    Incorrect boundary conditions in the Graphics: WebGPU component
+  * CVE-2026-16359 (bmo#2045424)
+    Incorrect boundary conditions in the Audio/Video: GMP component
+  * CVE-2026-16394 (bmo#2046748)
+    Mitigation bypass in the DOM: Security component
+  * CVE-2026-16395 (bmo#2047221)
+    Integer overflow in the Audio/Video component
+  * CVE-2026-16396 (bmo#2047240)
+    Privilege escalation in WebExtensions
+  * CVE-2026-16397 (bmo#2047608)
+    Clickjacking issue in the WebExtensions component in Firefox
+    for Android
+  * CVE-2026-16398 (bmo#2048345)
+    Site isolation issue in the Graphics component
+  * CVE-2026-16399 (bmo#2049981)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-16400 (bmo#2050430)
+    Information disclosure in the DOM: Security component
+  * CVE-2026-16401 (bmo#2052565)
+    Privilege escalation in the Data Loss Prevention component
+  * CVE-2026-16402 (bmo#2052703)
+    Integer overflow in the Graphics: ImageLib component
+  * CVE-2026-16403 (bmo#1972244)
+    Spoofing issue in the Address Bar component
+  * CVE-2026-16404 (bmo#2020253)
+    Spoofing issue in Firefox for Android
+  * CVE-2026-16405 (bmo#2036591)
+    Information disclosure in the Networking: WebSockets component
+  * CVE-2026-16406 (bmo#2040382)
+    Mitigation bypass in the Networking component
+  * CVE-2026-16407 (bmo#2044063)
+    Mitigation bypass in the DOM: Service Workers component
+  * CVE-2026-16408 (bmo#2050477)
+    Integer overflow in the Audio/Video: Playback component
+  * CVE-2026-16409 (bmo#2052134)
+    Invalid pointer in the Security: PSM component
+  * CVE-2026-16410 (bmo#2053680)
+    JIT miscompilation in the JavaScript Engine: JIT component
+  * CVE-2026-16411 (bmo#1420800, bmo#1598946, bmo#1767921, bmo#2006467,
+    bmo#2013993, bmo#2025417, bmo#2027325, bmo#2027346, bmo#2027349,
+    bmo#2027353, bmo#2027362, bmo#2027364, bmo#2027371, bmo#2027373,
+    bmo#2028954, bmo#2029433, bmo#2029694, bmo#2029807, bmo#2029901,
+    bmo#2029922, bmo#2030102, bmo#2030563, bmo#2032110, bmo#2036906,
+    bmo#2037801, bmo#2038964, bmo#2039460, bmo#2040522, bmo#2040834,
+    bmo#2042756, bmo#2043275, bmo#2044625, bmo#2045394, bmo#2045606,
+    bmo#2045609, bmo#2047920, bmo#2048491, bmo#2048492, bmo#2048800,
+    bmo#2048936, bmo#2049804, bmo#2050534, bmo#2050662, bmo#2050871,
+    bmo#2052060)
+    Memory safety bugs fixed in Firefox 153
+  * CVE-2026-16412 (bmo#2005113, bmo#2025369, bmo#2026301, bmo#2028663,
+    bmo#2029761, bmo#2042242, bmo#2043035, bmo#2043271, bmo#2043300,
+    bmo#2044612, bmo#2045057, bmo#2045187, bmo#2045378, bmo#2045402,
+    bmo#2045406, bmo#2045407, bmo#2045413, bmo#2045417, bmo#2045482,
+    bmo#2045611, bmo#2045616, bmo#2045618, bmo#2045626, bmo#2045730,
+    bmo#2045732, bmo#2045756, bmo#2045769, bmo#2045771, bmo#2046917,
+    bmo#2047718, bmo#2047957, bmo#2048934, bmo#2049818, bmo#2049822,
+    bmo#2050151, bmo#2050368, bmo#2051653, bmo#2051658, bmo#2053635,
+    bmo#2053637)
+    Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
+  * CVE-2026-16360 (bmo#2022635, bmo#2028004, bmo#2035756, bmo#2043739,
+    bmo#2045184, bmo#2045185, bmo#2045198, bmo#2045281, bmo#2045392,
+    bmo#2045395, bmo#2045396, bmo#2045397, bmo#2045405, bmo#2045414,
+    bmo#2045415, bmo#2045451, bmo#2045454, bmo#2045508, bmo#2045510,
+    bmo#2045513, bmo#2045515, bmo#2045518, bmo#2045604, bmo#2045607,
+    bmo#2045612, bmo#2045614, bmo#2045617, bmo#2045619, bmo#2045624,
+    bmo#2045625, bmo#2045729, bmo#2045737, bmo#2045741, bmo#2045742,
+    bmo#2045744, bmo#2045763, bmo#2045767, bmo#2045770, bmo#2045772,
+    bmo#2045773, bmo#2045775, bmo#2045783, bmo#2045833, bmo#2045848,
+    bmo#2045865, bmo#2045875, bmo#2045957, bmo#2047719, bmo#2047723,
+    bmo#2047729, bmo#2048795, bmo#2048799, bmo#2048801, bmo#2049392,
+    bmo#2049397, bmo#2049398, bmo#2049399, bmo#2049404, bmo#2049405,
+    bmo#2049407, bmo#2049805, bmo#2049812, bmo#2050657, bmo#2050668,
+    bmo#2050990, bmo#2051666, bmo#2053166, bmo#2053273, bmo#2053576,
+    bmo#2053583, bmo#2053587)
+    Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR
+    140.13 and Firefox 153
+- requires
+  NSS >= 3.125
+  rust-cbindgen >= 0.29.4
+- removed obsolete patches
+  mozilla-bmo1746799.patch
+  mozilla-bmo2041150.patch
+
+-------------------------------------------------------------------

Old:
----
  firefox-152.0.6.source.tar.xz
  firefox-152.0.6.source.tar.xz.asc
  l10n-152.0.6.tar.xz
  mozilla-bmo1746799.patch
  mozilla-bmo2041150.patch

New:
----
  firefox-153.0.source.tar.xz
  firefox-153.0.source.tar.xz.asc
  l10n-153.0.tar.xz

----------(Old B)----------
  Old:- removed obsolete patches
  mozilla-bmo1746799.patch
  mozilla-bmo2041150.patch
  Old:  mozilla-bmo1746799.patch
  mozilla-bmo2041150.patch
----------(Old E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ MozillaFirefox.spec ++++++
--- /var/tmp/diff_new_pack.ErGOtQ/_old  2026-07-23 23:11:00.157677764 +0200
+++ /var/tmp/diff_new_pack.ErGOtQ/_new  2026-07-23 23:11:00.157677764 +0200
@@ -28,9 +28,9 @@
 # orig_suffix b3
 # major 69
 # mainver %%major.99
-%define major          152
-%define mainver        %major.0.6
-%define orig_version   152.0.6
+%define major          153
+%define mainver        %major.0
+%define orig_version   153.0
 %define orig_suffix    %{nil}
 %define update_channel release
 %define branding       1
@@ -56,6 +56,11 @@
 %define useccache     0
 %endif
 
+# ccache doesn't work with pgo
+%if 0%{?do_profiling}
+%define useccache     0
+%endif
+
 # SLE-12 doesn't have this macro
 %{!?_rpmmacrodir: %global _rpmmacrodir %{_rpmconfigdir}/macros.d}
 
@@ -125,7 +130,7 @@
 BuildRequires:  libproxy-devel
 BuildRequires:  makeinfo
 BuildRequires:  mozilla-nspr-devel >= 4.39
-BuildRequires:  mozilla-nss-devel >= 3.124
+BuildRequires:  mozilla-nss-devel >= 3.125
 BuildRequires:  nasm >= 2.14
 BuildRequires:  nodejs >= 12.22.12
 %if 0%{?sle_version} >= 120000 && 0%{?sle_version} < 150000
@@ -148,8 +153,8 @@
 BuildRequires:  python3-devel
 %endif
 %endif
-BuildRequires:  rust-cbindgen >= 0.29.1
-%if 0%{?suse_version} > 1560
+BuildRequires:  rust-cbindgen >= 0.29.4
+%if 0%{?suse_version} >= 1699
 BuildRequires:  translate-suse-desktop
 %endif
 BuildRequires:  unzip
@@ -162,11 +167,8 @@
 %if 0%{?suse_version} < 1550
 BuildRequires:  pkgconfig(gconf-2.0) >= 1.2.1
 %endif
-%if 0%{?suse_version} < 1599
-BuildRequires:  clang19-devel
-%else
 BuildRequires:  clang-devel
-%endif
+#!BuildIgnore:  clang-tools
 BuildRequires:  pkgconfig(glib-2.0) >= 2.22
 BuildRequires:  pkgconfig(gobject-2.0)
 BuildRequires:  pkgconfig(gtk+-3.0) >= 3.14.0
@@ -234,10 +236,8 @@
 Patch18:        mozilla-silence-no-return-type.patch
 Patch20:        one_swizzle_to_rule_them_all.patch
 Patch21:        svg-rendering.patch
-Patch24:        mozilla-bmo1746799.patch
 Patch25:        mozilla-sandbox-lto.patch
 Patch26:        mozilla-bmo2030493.patch
-Patch27:        mozilla-bmo2041150.patch
 Patch28:        mozilla-bmo2048250.patch
 # Firefox/browser
 Patch102:       firefox-branded-icons.patch
@@ -345,7 +345,7 @@
 %else
 %setup -q -n %{srcname}-%{orig_version}
 %endif
-%if 0%{?suse_version} > 1560
+%if 0%{?suse_version} >= 1699
 cp %{SOURCE1} %{desktop_file_name}.desktop.in.in
 %else
 cp %{SOURCE5} %{desktop_file_name}.desktop
@@ -356,7 +356,7 @@
 
 %build
 # desktop file
-%if 0%{?suse_version} > 1560
+%if 0%{?suse_version} >= 1699
 sed "s:%%NAME:%{appname}:g
 s:%%EXEC:%{progname}:g
 s:%%ICON:%{progname}:g

++++++ firefox-152.0.6.source.tar.xz -> firefox-153.0.source.tar.xz ++++++
/work/SRC/openSUSE:Factory/MozillaFirefox/firefox-152.0.6.source.tar.xz 
/work/SRC/openSUSE:Factory/.MozillaFirefox.new.2004/firefox-153.0.source.tar.xz 
differ: char 15, line 1

++++++ l10n-152.0.6.tar.xz -> l10n-153.0.tar.xz ++++++
/work/SRC/openSUSE:Factory/MozillaFirefox/l10n-152.0.6.tar.xz 
/work/SRC/openSUSE:Factory/.MozillaFirefox.new.2004/l10n-153.0.tar.xz differ: 
char 15, line 1

++++++ mozilla-silence-no-return-type.patch ++++++
++++ 1464 lines (skipped)
++++ between 
/work/SRC/openSUSE:Factory/MozillaFirefox/mozilla-silence-no-return-type.patch
++++ and 
/work/SRC/openSUSE:Factory/.MozillaFirefox.new.2004/mozilla-silence-no-return-type.patch

++++++ tar_stamps ++++++
--- /var/tmp/diff_new_pack.ErGOtQ/_old  2026-07-23 23:11:00.673695883 +0200
+++ /var/tmp/diff_new_pack.ErGOtQ/_new  2026-07-23 23:11:00.677696024 +0200
@@ -1,11 +1,11 @@
 PRODUCT="firefox"
 CHANNEL="release"
-VERSION="152.0.6"
+VERSION="153.0"
 VERSION_SUFFIX=""
-PREV_VERSION="152.0.5"
+PREV_VERSION="140.13.0"
 PREV_VERSION_SUFFIX=""
 #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
 RELEASE_REPO="https://hg.mozilla.org/releases/mozilla-release";
-RELEASE_TAG="68dfbca029f49cab85d965451998997141758306"
-RELEASE_TIMESTAMP="20260713164047"
+RELEASE_TAG="3810496e857367d04cf4fa0c705df6995a48b860"
+RELEASE_TIMESTAMP="20260715202819"
 

Reply via email to