Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package firefox-esr for openSUSE:Factory 
checked in at 2026-09-02 16:58:38
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/firefox-esr (Old)
 and      /work/SRC/openSUSE:Factory/.firefox-esr.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "firefox-esr"

Wed Sep  2 16:58:38 2026 rev:42 rq:1375309 version:153.2.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/firefox-esr/MozillaFirefox.changes       
2026-08-19 17:56:57.098049723 +0200
+++ /work/SRC/openSUSE:Factory/.firefox-esr.new.1265/MozillaFirefox.changes     
2026-09-02 16:58:44.276998463 +0200
@@ -1,0 +2,87 @@
+Tue Sep  1 14:50:33 UTC 2026 - Bernhard Wiedemann <[email protected]>
+
+- Disable PGO when a reproducible build is wanted (boo#1040589)
+
+-------------------------------------------------------------------
+Tue Sep  1 12:23:49 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 153.2.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 153.2.0
+  https://www.mozilla.org/security/advisories/mfsa2026-85
+  MFSA 2026-85 (boo#1278001)
+  * CVE-2026-75874 (bmo#2039972)
+    Sandbox escape in the Remote Settings Client component
+  * CVE-2026-84118 (bmo#2057457)
+    Use-after-free in the JavaScript: GC component
+  * CVE-2026-84119 (bmo#2057817)
+    Sandbox escape due to use-after-free in the DOM: Navigation
+    component
+  * CVE-2026-84120 (bmo#2058911)
+    Use-after-free in the Audio/Video component
+  * CVE-2026-84121 (bmo#2059018)
+    Sandbox escape due to use-after-free in the DOM: Security
+    component
+  * CVE-2026-84122 (bmo#2059965)
+    Use-after-free in the Audio/Video component
+  * CVE-2026-84123 (bmo#2060047)
+    Privilege escalation due to use-after-free in the Graphics:
+    WebGPU component
+  * CVE-2026-84124 (bmo#2061110)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-84125 (bmo#2063871)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-74952 (bmo#2021757)
+    Privilege escalation in the Application Update component
+  * CVE-2026-84129 (bmo#2055028)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-84130 (bmo#2057834)
+    Information disclosure in the Graphics: WebGPU component
+  * CVE-2026-84131 (bmo#2060008)
+    Privilege escalation due to invalid pointer in the Graphics
+    component
+  * CVE-2026-84132 (bmo#2063020)
+    Information disclosure in the Networking: HTTP component
+  * CVE-2026-84133 (bmo#2032388)
+    Site isolation issue in the DOM: Push Subscriptions component
+  * CVE-2026-84134 (bmo#2044882)
+    Other issue in the Profile Backup component
+  * CVE-2026-84136 (bmo#2048699)
+    Other issue in the DOM: Navigation component
+  * CVE-2026-84137 (bmo#2051146)
+    Spoofing issue in the DOM: Core & HTML component
+  * CVE-2026-84139 (bmo#2060153)
+    Clickjacking issue in the DOM: Events component
+  * CVE-2026-84140 (bmo#2063780)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-84141 (bmo#2063994)
+    Integer overflow in the Graphics: ImageLib component
+  * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645,
+    bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107,
+    bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088,
+    bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109,
+    bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301,
+    bmo#2061325)
+    Internally found bugs fixed in Firefox 155, Firefox ESR 153.2
+    and Firefox ESR 140.15
+  * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624,
+    bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726,
+    bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013,
+    bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661,
+    bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144,
+    bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199,
+    bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495,
+    bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775,
+    bmo#2061799, bmo#2062395, bmo#2062404)
+    Internally found bugs fixed in Firefox 155 and Firefox ESR
+    153.2
+  * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652,
+    bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001,
+    bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027,
+    bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285,
+    bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400,
+    bmo#2062419)
+    Internally found bugs fixed in Firefox 155, Firefox ESR
+    153.2, Firefox ESR 140.15 and Firefox ESR 115.40
+
+-------------------------------------------------------------------
firefox-esr.changes: same change

Old:
----
  firefox-153.1.0esr.source.tar.xz
  firefox-153.1.0esr.source.tar.xz.asc
  l10n-153.1.0esr.tar.xz

New:
----
  firefox-153.2.0esr.source.tar.xz
  firefox-153.2.0esr.source.tar.xz.asc
  l10n-153.2.0esr.tar.xz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ firefox-esr.spec ++++++
--- /var/tmp/diff_new_pack.xmxHdx/_old  2026-09-02 16:59:14.224039526 +0200
+++ /var/tmp/diff_new_pack.xmxHdx/_new  2026-09-02 16:59:14.228039665 +0200
@@ -41,13 +41,16 @@
 # major 69
 # mainver %%major.99
 %define major          153
-%define mainver        %major.1.0
-%define orig_version   153.1.0
+%define mainver        %major.2.0
+%define orig_version   153.2.0
 %define orig_suffix    esr
 %define update_channel esr
 %define branding       1
 %define devpkg         0
 %define do_profiling   1
+%if 0%{?want_reproducible_builds}
+%define do_profiling   0
+%endif
 
 # upstream default is clang (to use gcc for large parts set to 0)
 %define clang_build    0

++++++ MozillaFirefox.changes.txt ++++++
--- /var/tmp/diff_new_pack.xmxHdx/_old  2026-09-02 16:59:14.339043524 +0200
+++ /var/tmp/diff_new_pack.xmxHdx/_new  2026-09-02 16:59:14.344043698 +0200
@@ -1,4 +1,91 @@
 -------------------------------------------------------------------
+Tue Sep  1 14:50:33 UTC 2026 - Bernhard Wiedemann <[email protected]>
+
+- Disable PGO when a reproducible build is wanted (boo#1040589)
+
+-------------------------------------------------------------------
+Tue Sep  1 12:23:49 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 153.2.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 153.2.0
+  https://www.mozilla.org/security/advisories/mfsa2026-85
+  MFSA 2026-85 (boo#1278001)
+  * CVE-2026-75874 (bmo#2039972)
+    Sandbox escape in the Remote Settings Client component
+  * CVE-2026-84118 (bmo#2057457)
+    Use-after-free in the JavaScript: GC component
+  * CVE-2026-84119 (bmo#2057817)
+    Sandbox escape due to use-after-free in the DOM: Navigation
+    component
+  * CVE-2026-84120 (bmo#2058911)
+    Use-after-free in the Audio/Video component
+  * CVE-2026-84121 (bmo#2059018)
+    Sandbox escape due to use-after-free in the DOM: Security
+    component
+  * CVE-2026-84122 (bmo#2059965)
+    Use-after-free in the Audio/Video component
+  * CVE-2026-84123 (bmo#2060047)
+    Privilege escalation due to use-after-free in the Graphics:
+    WebGPU component
+  * CVE-2026-84124 (bmo#2061110)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-84125 (bmo#2063871)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-74952 (bmo#2021757)
+    Privilege escalation in the Application Update component
+  * CVE-2026-84129 (bmo#2055028)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-84130 (bmo#2057834)
+    Information disclosure in the Graphics: WebGPU component
+  * CVE-2026-84131 (bmo#2060008)
+    Privilege escalation due to invalid pointer in the Graphics
+    component
+  * CVE-2026-84132 (bmo#2063020)
+    Information disclosure in the Networking: HTTP component
+  * CVE-2026-84133 (bmo#2032388)
+    Site isolation issue in the DOM: Push Subscriptions component
+  * CVE-2026-84134 (bmo#2044882)
+    Other issue in the Profile Backup component
+  * CVE-2026-84136 (bmo#2048699)
+    Other issue in the DOM: Navigation component
+  * CVE-2026-84137 (bmo#2051146)
+    Spoofing issue in the DOM: Core & HTML component
+  * CVE-2026-84139 (bmo#2060153)
+    Clickjacking issue in the DOM: Events component
+  * CVE-2026-84140 (bmo#2063780)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-84141 (bmo#2063994)
+    Integer overflow in the Graphics: ImageLib component
+  * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645,
+    bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107,
+    bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088,
+    bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109,
+    bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301,
+    bmo#2061325)
+    Internally found bugs fixed in Firefox 155, Firefox ESR 153.2
+    and Firefox ESR 140.15
+  * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624,
+    bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726,
+    bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013,
+    bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661,
+    bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144,
+    bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199,
+    bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495,
+    bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775,
+    bmo#2061799, bmo#2062395, bmo#2062404)
+    Internally found bugs fixed in Firefox 155 and Firefox ESR
+    153.2
+  * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652,
+    bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001,
+    bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027,
+    bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285,
+    bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400,
+    bmo#2062419)
+    Internally found bugs fixed in Firefox 155, Firefox ESR
+    153.2, Firefox ESR 140.15 and Firefox ESR 115.40
+
+-------------------------------------------------------------------
 Wed Aug 19 11:20:04 UTC 2026 - Manfred Hollstein <[email protected]>
 
 - Disable ccache again; reasons remain the same as documented by

++++++ firefox-153.1.0esr.source.tar.xz -> firefox-153.2.0esr.source.tar.xz 
++++++
/work/SRC/openSUSE:Factory/firefox-esr/firefox-153.1.0esr.source.tar.xz 
/work/SRC/openSUSE:Factory/.firefox-esr.new.1265/firefox-153.2.0esr.source.tar.xz
 differ: char 15, line 1

++++++ firefox-esr.changes.txt ++++++
--- /var/tmp/diff_new_pack.xmxHdx/_old  2026-09-02 16:59:14.459047696 +0200
+++ /var/tmp/diff_new_pack.xmxHdx/_new  2026-09-02 16:59:14.465047905 +0200
@@ -1,4 +1,91 @@
 -------------------------------------------------------------------
+Tue Sep  1 14:50:33 UTC 2026 - Bernhard Wiedemann <[email protected]>
+
+- Disable PGO when a reproducible build is wanted (boo#1040589)
+
+-------------------------------------------------------------------
+Tue Sep  1 12:23:49 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 153.2.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 153.2.0
+  https://www.mozilla.org/security/advisories/mfsa2026-85
+  MFSA 2026-85 (boo#1278001)
+  * CVE-2026-75874 (bmo#2039972)
+    Sandbox escape in the Remote Settings Client component
+  * CVE-2026-84118 (bmo#2057457)
+    Use-after-free in the JavaScript: GC component
+  * CVE-2026-84119 (bmo#2057817)
+    Sandbox escape due to use-after-free in the DOM: Navigation
+    component
+  * CVE-2026-84120 (bmo#2058911)
+    Use-after-free in the Audio/Video component
+  * CVE-2026-84121 (bmo#2059018)
+    Sandbox escape due to use-after-free in the DOM: Security
+    component
+  * CVE-2026-84122 (bmo#2059965)
+    Use-after-free in the Audio/Video component
+  * CVE-2026-84123 (bmo#2060047)
+    Privilege escalation due to use-after-free in the Graphics:
+    WebGPU component
+  * CVE-2026-84124 (bmo#2061110)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-84125 (bmo#2063871)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-74952 (bmo#2021757)
+    Privilege escalation in the Application Update component
+  * CVE-2026-84129 (bmo#2055028)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-84130 (bmo#2057834)
+    Information disclosure in the Graphics: WebGPU component
+  * CVE-2026-84131 (bmo#2060008)
+    Privilege escalation due to invalid pointer in the Graphics
+    component
+  * CVE-2026-84132 (bmo#2063020)
+    Information disclosure in the Networking: HTTP component
+  * CVE-2026-84133 (bmo#2032388)
+    Site isolation issue in the DOM: Push Subscriptions component
+  * CVE-2026-84134 (bmo#2044882)
+    Other issue in the Profile Backup component
+  * CVE-2026-84136 (bmo#2048699)
+    Other issue in the DOM: Navigation component
+  * CVE-2026-84137 (bmo#2051146)
+    Spoofing issue in the DOM: Core & HTML component
+  * CVE-2026-84139 (bmo#2060153)
+    Clickjacking issue in the DOM: Events component
+  * CVE-2026-84140 (bmo#2063780)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-84141 (bmo#2063994)
+    Integer overflow in the Graphics: ImageLib component
+  * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645,
+    bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107,
+    bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088,
+    bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109,
+    bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301,
+    bmo#2061325)
+    Internally found bugs fixed in Firefox 155, Firefox ESR 153.2
+    and Firefox ESR 140.15
+  * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624,
+    bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726,
+    bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013,
+    bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661,
+    bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144,
+    bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199,
+    bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495,
+    bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775,
+    bmo#2061799, bmo#2062395, bmo#2062404)
+    Internally found bugs fixed in Firefox 155 and Firefox ESR
+    153.2
+  * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652,
+    bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001,
+    bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027,
+    bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285,
+    bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400,
+    bmo#2062419)
+    Internally found bugs fixed in Firefox 155, Firefox ESR
+    153.2, Firefox ESR 140.15 and Firefox ESR 115.40
+
+-------------------------------------------------------------------
 Wed Aug 19 11:20:04 UTC 2026 - Manfred Hollstein <[email protected]>
 
 - Disable ccache again; reasons remain the same as documented by

++++++ l10n-153.1.0esr.tar.xz -> l10n-153.2.0esr.tar.xz ++++++
/work/SRC/openSUSE:Factory/firefox-esr/l10n-153.1.0esr.tar.xz 
/work/SRC/openSUSE:Factory/.firefox-esr.new.1265/l10n-153.2.0esr.tar.xz differ: 
char 15, line 1

++++++ tar_stamps ++++++
--- /var/tmp/diff_new_pack.xmxHdx/_old  2026-09-02 16:59:14.707056318 +0200
+++ /var/tmp/diff_new_pack.xmxHdx/_new  2026-09-02 16:59:14.712056491 +0200
@@ -1,11 +1,11 @@
 PRODUCT="firefox"
 CHANNEL="esr153"
-VERSION="153.1.0"
+VERSION="153.2.0"
 VERSION_SUFFIX="esr"
-PREV_VERSION="153.0"
+PREV_VERSION="153.1.0"
 PREV_VERSION_SUFFIX="esr"
 #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
 RELEASE_REPO="https://hg.mozilla.org/releases/mozilla-esr153";
-RELEASE_TAG="bdb74c45c2e1e3fe593fbf3c5ca6d2ab2046ef08"
-RELEASE_TIMESTAMP="20260811201151"
+RELEASE_TAG="92c5bf513a3e4e39fa70df2df6a565a1049a9920"
+RELEASE_TIMESTAMP="20260826022508"
 

Reply via email to