1 UPDATED package firefox-esr - The Mozilla Firefox project is a redesign of Mozilla's browser [640M] * Fri Jun 26 2026 Pavel Vasenkov <pav@altlinux> 140.12.0-alt0.p10.1 - Backport new version. * Thu Jun 18 2026 Pavel Vasenkov <pav@altlinux> 140.12.0-alt1 - New ESR version. - Security fixes: + CVE-2026-12289 Privilege escalation in the Graphics: WebRender component + CVE-2026-12290 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12291 Use-after-free in the Networking: HTTP component + CVE-2026-12292 Incorrect boundary conditions in the Web Audio component + CVE-2026-12294 Sandbox escape in the DOM: Workers component + CVE-2026-12295 Sandbox escape in the DOM: Navigation component + CVE-2026-12298 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12296 Sandbox escape in the Security: Process Sandboxing component + CVE-2026-12297 Sandbox escape due to incorrect boundary conditions in the Networking component + CVE-2026-12299 JIT miscompilation in the DOM: Core & HTML component + CVE-2026-12329 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12302 Mitigation bypass in the DOM: Security component + CVE-2026-12304 Same-origin policy bypass in the Networking: Cookies component + CVE-2026-12305 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12306 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12307 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12308 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12309 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12310 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12311 Information disclosure, sandbox escape in the Security: Process Sandboxing component + CVE-2026-12312 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12313 Information disclosure, sandbox escape in the Security: Process Sandboxing component + CVE-2026-12314 Memory safety bug fixed in Firefox ESR 140.12 + CVE-2026-12315 Mitigation bypass in the DOM: Security component + CVE-2026-12330 Incorrect boundary conditions in the Internationalization component + CVE-2026-12324 Incorrect boundary conditions in the Graphics: CanvasWebGL component + CVE-2026-12325 Denial-of-service in the Graphics: ImageLib component + CVE-2026-12327 Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 + CVE-2026-12328 Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 * Tue Jun 16 2026 Pavel Vasenkov <pav@altlinux> 140.11.0-alt2 - Fix FTBFS with glslopt once flag libc * Fri Jun 05 2026 Pavel Vasenkov <pav@altlinux> 140.11.0-alt1 - New ESR version. - Security fixes: + CVE-2026-8946 Incorrect boundary conditions in the Audio/Video: Web Codecs component + CVE-2026-8388 Incorrect boundary conditions in the JavaScript Engine: JIT component + CVE-2026-8947 Use-after-free in the DOM: Bindings (WebIDL) component + CVE-2026-8391 Other issue in the JavaScript Engine component + CVE-2026-8401 Sandbox escape in the Profile Backup component + CVE-2026-8949 Integer overflow in the Widget: Win32 component + CVE-2026-8950 Same-origin policy bypass in the Networking: HTTP component + CVE-2026-8953 Sandbox escape due to use-after-free in the Disability Access APIs component + CVE-2026-8954 Incorrect boundary conditions, integer overflow in the Audio/Video component + CVE-2026-8955 Privilege escalation in the DOM: Workers component + CVE-2026-8956 Integer overflow in the Networking: JAR component + CVE-2026-8957 Privilege escalation in the Enterprise Policies component + CVE-2026-8958 Information disclosure, sandbox escape in the Security: Process Sandboxing component + CVE-2026-8959 Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component + CVE-2026-8961 Spoofing issue in the Form Autofill component + CVE-2026-8962 Mitigation bypass in the DOM: Security component + CVE-2026-8968 Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component + CVE-2026-8970 Privilege escalation in the Security component + CVE-2026-8974 Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 + CVE-2026-8975 Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 * Thu Jun 04 2026 Pavel Vasenkov <pav@altlinux> 140.10.2-alt1 - New ESR version. - Security fixes: + CVE-2026-8090 Use-after-free in the DOM: Networking component + CVE-2026-8094 Other issue in the WebRTC component + CVE-2026-8092 Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 * Sun May 24 2026 Pavel Vasenkov <pav@altlinux> 140.10.1-alt1 - New ESR version. - Security fixes: + CVE-2026-7320 Information disclosure due to incorrect boundary conditions in the Audio/Video component + CVE-2026-7321 Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component + CVE-2026-8091 Incorrect boundary conditions in the Audio/Video: Playback component + CVE-2026-7322 Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1 + CVE-2026-7323 Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1 * Sun May 24 2026 Pavel Vasenkov <pav@altlinux> 140.10.0-alt1 - New ESR version. - Security fixes: + CVE-2026-6746 Use-after-free in the DOM: Core & HTML component + CVE-2026-6747 Use-after-free in the WebRTC component + CVE-2026-6748 Uninitialized memory in the Audio/Video: Web Codecs component + CVE-2026-6749 Information disclosure due to uninitialized memory in the Graphics: Canvas2D component + CVE-2026-6750 Privilege escalation in the Graphics: WebRender component + CVE-2026-6751 Uninitialized memory in the Audio/Video: Web Codecs component + CVE-2026-6752 Incorrect boundary conditions in the WebRTC component + CVE-2026-6753 Incorrect boundary conditions in the WebRTC component + CVE-2026-6754 Use-after-free in the JavaScript Engine component + CVE-2026-6757 Invalid pointer in the JavaScript: WebAssembly component + CVE-2026-6759 Use-after-free in the Widget: Cocoa component + CVE-2026-6761 Privilege escalation in the Networking component + CVE-2026-6762 Spoofing issue in the DOM: Core & HTML component + CVE-2026-6763 Mitigation bypass in the File Handling component + CVE-2026-6764 Incorrect boundary conditions in the DOM: Device Interfaces component + CVE-2026-6765 Information disclosure in the Form Autofill component + CVE-2026-6766 Incorrect boundary conditions in the Libraries component in NSS + CVE-2026-6767 Other issue in the Libraries component in NSS + CVE-2026-6769 Privilege escalation in the Debugger component + CVE-2026-6770 Other issue in the Storage: IndexedDB component + CVE-2026-6771 Mitigation bypass in the DOM: Security component + CVE-2026-6772 Incorrect boundary conditions in the Libraries component in NSS + CVE-2026-6776 Incorrect boundary conditions in the WebRTC: Networking component + CVE-2026-6785 Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 + CVE-2026-6786 Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 * Sat Apr 11 2026 Pavel Vasenkov <pav@altlinux> 140.9.1-alt1 - New ESR version. - Security fixes: + CVE-2026-5732 Incorrect boundary conditions, integer overflow in the Graphics: Text component + CVE-2026-5731 Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird + CVE-2026-5734 Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 * Fri Mar 27 2026 Pavel Vasenkov <pav@altlinux> 140.9.0-alt1 Note: changelog entry for 140.9.1-alt0.p10.1 not found.
Total 19171 source packages. _______________________________________________ Sisyphus-cybertalk mailing list [email protected] https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk
