Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package firefox-esr for openSUSE:Factory checked in at 2026-09-02 16:58:38 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/firefox-esr (Old) and /work/SRC/openSUSE:Factory/.firefox-esr.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "firefox-esr" Wed Sep 2 16:58:38 2026 rev:42 rq:1375309 version:153.2.0 Changes: -------- --- /work/SRC/openSUSE:Factory/firefox-esr/MozillaFirefox.changes 2026-08-19 17:56:57.098049723 +0200 +++ /work/SRC/openSUSE:Factory/.firefox-esr.new.1265/MozillaFirefox.changes 2026-09-02 16:58:44.276998463 +0200 @@ -1,0 +2,87 @@ +Tue Sep 1 14:50:33 UTC 2026 - Bernhard Wiedemann <[email protected]> + +- Disable PGO when a reproducible build is wanted (boo#1040589) + +------------------------------------------------------------------- +Tue Sep 1 12:23:49 UTC 2026 - Manfred Hollstein <[email protected]> + +- Firefox Extended Support Release 153.2.0 ESR + * Fixed: Various security fixes. +- Mozilla Firefox ESR 153.2.0 + https://www.mozilla.org/security/advisories/mfsa2026-85 + MFSA 2026-85 (boo#1278001) + * CVE-2026-75874 (bmo#2039972) + Sandbox escape in the Remote Settings Client component + * CVE-2026-84118 (bmo#2057457) + Use-after-free in the JavaScript: GC component + * CVE-2026-84119 (bmo#2057817) + Sandbox escape due to use-after-free in the DOM: Navigation + component + * CVE-2026-84120 (bmo#2058911) + Use-after-free in the Audio/Video component + * CVE-2026-84121 (bmo#2059018) + Sandbox escape due to use-after-free in the DOM: Security + component + * CVE-2026-84122 (bmo#2059965) + Use-after-free in the Audio/Video component + * CVE-2026-84123 (bmo#2060047) + Privilege escalation due to use-after-free in the Graphics: + WebGPU component + * CVE-2026-84124 (bmo#2061110) + Use-after-free in the DOM: Core & HTML component + * CVE-2026-84125 (bmo#2063871) + Use-after-free in the DOM: Core & HTML component + * CVE-2026-74952 (bmo#2021757) + Privilege escalation in the Application Update component + * CVE-2026-84129 (bmo#2055028) + Site isolation issue in the DOM: Navigation component + * CVE-2026-84130 (bmo#2057834) + Information disclosure in the Graphics: WebGPU component + * CVE-2026-84131 (bmo#2060008) + Privilege escalation due to invalid pointer in the Graphics + component + * CVE-2026-84132 (bmo#2063020) + Information disclosure in the Networking: HTTP component + * CVE-2026-84133 (bmo#2032388) + Site isolation issue in the DOM: Push Subscriptions component + * CVE-2026-84134 (bmo#2044882) + Other issue in the Profile Backup component + * CVE-2026-84136 (bmo#2048699) + Other issue in the DOM: Navigation component + * CVE-2026-84137 (bmo#2051146) + Spoofing issue in the DOM: Core & HTML component + * CVE-2026-84139 (bmo#2060153) + Clickjacking issue in the DOM: Events component + * CVE-2026-84140 (bmo#2063780) + Site isolation issue in the DOM: Navigation component + * CVE-2026-84141 (bmo#2063994) + Integer overflow in the Graphics: ImageLib component + * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, + bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107, + bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088, + bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109, + bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301, + bmo#2061325) + Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 + and Firefox ESR 140.15 + * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624, + bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726, + bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013, + bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661, + bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144, + bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199, + bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495, + bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775, + bmo#2061799, bmo#2062395, bmo#2062404) + Internally found bugs fixed in Firefox 155 and Firefox ESR + 153.2 + * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, + bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001, + bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027, + bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285, + bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400, + bmo#2062419) + Internally found bugs fixed in Firefox 155, Firefox ESR + 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 + +------------------------------------------------------------------- firefox-esr.changes: same change Old: ---- firefox-153.1.0esr.source.tar.xz firefox-153.1.0esr.source.tar.xz.asc l10n-153.1.0esr.tar.xz New: ---- firefox-153.2.0esr.source.tar.xz firefox-153.2.0esr.source.tar.xz.asc l10n-153.2.0esr.tar.xz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ firefox-esr.spec ++++++ --- /var/tmp/diff_new_pack.xmxHdx/_old 2026-09-02 16:59:14.224039526 +0200 +++ /var/tmp/diff_new_pack.xmxHdx/_new 2026-09-02 16:59:14.228039665 +0200 @@ -41,13 +41,16 @@ # major 69 # mainver %%major.99 %define major 153 -%define mainver %major.1.0 -%define orig_version 153.1.0 +%define mainver %major.2.0 +%define orig_version 153.2.0 %define orig_suffix esr %define update_channel esr %define branding 1 %define devpkg 0 %define do_profiling 1 +%if 0%{?want_reproducible_builds} +%define do_profiling 0 +%endif # upstream default is clang (to use gcc for large parts set to 0) %define clang_build 0 ++++++ MozillaFirefox.changes.txt ++++++ --- /var/tmp/diff_new_pack.xmxHdx/_old 2026-09-02 16:59:14.339043524 +0200 +++ /var/tmp/diff_new_pack.xmxHdx/_new 2026-09-02 16:59:14.344043698 +0200 @@ -1,4 +1,91 @@ ------------------------------------------------------------------- +Tue Sep 1 14:50:33 UTC 2026 - Bernhard Wiedemann <[email protected]> + +- Disable PGO when a reproducible build is wanted (boo#1040589) + +------------------------------------------------------------------- +Tue Sep 1 12:23:49 UTC 2026 - Manfred Hollstein <[email protected]> + +- Firefox Extended Support Release 153.2.0 ESR + * Fixed: Various security fixes. +- Mozilla Firefox ESR 153.2.0 + https://www.mozilla.org/security/advisories/mfsa2026-85 + MFSA 2026-85 (boo#1278001) + * CVE-2026-75874 (bmo#2039972) + Sandbox escape in the Remote Settings Client component + * CVE-2026-84118 (bmo#2057457) + Use-after-free in the JavaScript: GC component + * CVE-2026-84119 (bmo#2057817) + Sandbox escape due to use-after-free in the DOM: Navigation + component + * CVE-2026-84120 (bmo#2058911) + Use-after-free in the Audio/Video component + * CVE-2026-84121 (bmo#2059018) + Sandbox escape due to use-after-free in the DOM: Security + component + * CVE-2026-84122 (bmo#2059965) + Use-after-free in the Audio/Video component + * CVE-2026-84123 (bmo#2060047) + Privilege escalation due to use-after-free in the Graphics: + WebGPU component + * CVE-2026-84124 (bmo#2061110) + Use-after-free in the DOM: Core & HTML component + * CVE-2026-84125 (bmo#2063871) + Use-after-free in the DOM: Core & HTML component + * CVE-2026-74952 (bmo#2021757) + Privilege escalation in the Application Update component + * CVE-2026-84129 (bmo#2055028) + Site isolation issue in the DOM: Navigation component + * CVE-2026-84130 (bmo#2057834) + Information disclosure in the Graphics: WebGPU component + * CVE-2026-84131 (bmo#2060008) + Privilege escalation due to invalid pointer in the Graphics + component + * CVE-2026-84132 (bmo#2063020) + Information disclosure in the Networking: HTTP component + * CVE-2026-84133 (bmo#2032388) + Site isolation issue in the DOM: Push Subscriptions component + * CVE-2026-84134 (bmo#2044882) + Other issue in the Profile Backup component + * CVE-2026-84136 (bmo#2048699) + Other issue in the DOM: Navigation component + * CVE-2026-84137 (bmo#2051146) + Spoofing issue in the DOM: Core & HTML component + * CVE-2026-84139 (bmo#2060153) + Clickjacking issue in the DOM: Events component + * CVE-2026-84140 (bmo#2063780) + Site isolation issue in the DOM: Navigation component + * CVE-2026-84141 (bmo#2063994) + Integer overflow in the Graphics: ImageLib component + * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, + bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107, + bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088, + bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109, + bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301, + bmo#2061325) + Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 + and Firefox ESR 140.15 + * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624, + bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726, + bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013, + bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661, + bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144, + bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199, + bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495, + bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775, + bmo#2061799, bmo#2062395, bmo#2062404) + Internally found bugs fixed in Firefox 155 and Firefox ESR + 153.2 + * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, + bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001, + bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027, + bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285, + bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400, + bmo#2062419) + Internally found bugs fixed in Firefox 155, Firefox ESR + 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 + +------------------------------------------------------------------- Wed Aug 19 11:20:04 UTC 2026 - Manfred Hollstein <[email protected]> - Disable ccache again; reasons remain the same as documented by ++++++ firefox-153.1.0esr.source.tar.xz -> firefox-153.2.0esr.source.tar.xz ++++++ /work/SRC/openSUSE:Factory/firefox-esr/firefox-153.1.0esr.source.tar.xz /work/SRC/openSUSE:Factory/.firefox-esr.new.1265/firefox-153.2.0esr.source.tar.xz differ: char 15, line 1 ++++++ firefox-esr.changes.txt ++++++ --- /var/tmp/diff_new_pack.xmxHdx/_old 2026-09-02 16:59:14.459047696 +0200 +++ /var/tmp/diff_new_pack.xmxHdx/_new 2026-09-02 16:59:14.465047905 +0200 @@ -1,4 +1,91 @@ ------------------------------------------------------------------- +Tue Sep 1 14:50:33 UTC 2026 - Bernhard Wiedemann <[email protected]> + +- Disable PGO when a reproducible build is wanted (boo#1040589) + +------------------------------------------------------------------- +Tue Sep 1 12:23:49 UTC 2026 - Manfred Hollstein <[email protected]> + +- Firefox Extended Support Release 153.2.0 ESR + * Fixed: Various security fixes. +- Mozilla Firefox ESR 153.2.0 + https://www.mozilla.org/security/advisories/mfsa2026-85 + MFSA 2026-85 (boo#1278001) + * CVE-2026-75874 (bmo#2039972) + Sandbox escape in the Remote Settings Client component + * CVE-2026-84118 (bmo#2057457) + Use-after-free in the JavaScript: GC component + * CVE-2026-84119 (bmo#2057817) + Sandbox escape due to use-after-free in the DOM: Navigation + component + * CVE-2026-84120 (bmo#2058911) + Use-after-free in the Audio/Video component + * CVE-2026-84121 (bmo#2059018) + Sandbox escape due to use-after-free in the DOM: Security + component + * CVE-2026-84122 (bmo#2059965) + Use-after-free in the Audio/Video component + * CVE-2026-84123 (bmo#2060047) + Privilege escalation due to use-after-free in the Graphics: + WebGPU component + * CVE-2026-84124 (bmo#2061110) + Use-after-free in the DOM: Core & HTML component + * CVE-2026-84125 (bmo#2063871) + Use-after-free in the DOM: Core & HTML component + * CVE-2026-74952 (bmo#2021757) + Privilege escalation in the Application Update component + * CVE-2026-84129 (bmo#2055028) + Site isolation issue in the DOM: Navigation component + * CVE-2026-84130 (bmo#2057834) + Information disclosure in the Graphics: WebGPU component + * CVE-2026-84131 (bmo#2060008) + Privilege escalation due to invalid pointer in the Graphics + component + * CVE-2026-84132 (bmo#2063020) + Information disclosure in the Networking: HTTP component + * CVE-2026-84133 (bmo#2032388) + Site isolation issue in the DOM: Push Subscriptions component + * CVE-2026-84134 (bmo#2044882) + Other issue in the Profile Backup component + * CVE-2026-84136 (bmo#2048699) + Other issue in the DOM: Navigation component + * CVE-2026-84137 (bmo#2051146) + Spoofing issue in the DOM: Core & HTML component + * CVE-2026-84139 (bmo#2060153) + Clickjacking issue in the DOM: Events component + * CVE-2026-84140 (bmo#2063780) + Site isolation issue in the DOM: Navigation component + * CVE-2026-84141 (bmo#2063994) + Integer overflow in the Graphics: ImageLib component + * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, + bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107, + bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088, + bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109, + bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301, + bmo#2061325) + Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 + and Firefox ESR 140.15 + * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624, + bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726, + bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013, + bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661, + bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144, + bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199, + bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495, + bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775, + bmo#2061799, bmo#2062395, bmo#2062404) + Internally found bugs fixed in Firefox 155 and Firefox ESR + 153.2 + * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, + bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001, + bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027, + bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285, + bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400, + bmo#2062419) + Internally found bugs fixed in Firefox 155, Firefox ESR + 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 + +------------------------------------------------------------------- Wed Aug 19 11:20:04 UTC 2026 - Manfred Hollstein <[email protected]> - Disable ccache again; reasons remain the same as documented by ++++++ l10n-153.1.0esr.tar.xz -> l10n-153.2.0esr.tar.xz ++++++ /work/SRC/openSUSE:Factory/firefox-esr/l10n-153.1.0esr.tar.xz /work/SRC/openSUSE:Factory/.firefox-esr.new.1265/l10n-153.2.0esr.tar.xz differ: char 15, line 1 ++++++ tar_stamps ++++++ --- /var/tmp/diff_new_pack.xmxHdx/_old 2026-09-02 16:59:14.707056318 +0200 +++ /var/tmp/diff_new_pack.xmxHdx/_new 2026-09-02 16:59:14.712056491 +0200 @@ -1,11 +1,11 @@ PRODUCT="firefox" CHANNEL="esr153" -VERSION="153.1.0" +VERSION="153.2.0" VERSION_SUFFIX="esr" -PREV_VERSION="153.0" +PREV_VERSION="153.1.0" PREV_VERSION_SUFFIX="esr" #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation RELEASE_REPO="https://hg.mozilla.org/releases/mozilla-esr153" -RELEASE_TAG="bdb74c45c2e1e3fe593fbf3c5ca6d2ab2046ef08" -RELEASE_TIMESTAMP="20260811201151" +RELEASE_TAG="92c5bf513a3e4e39fa70df2df6a565a1049a9920" +RELEASE_TIMESTAMP="20260826022508"
