Lector de Feeds

MGASA-2026-0357 - Updated varnish packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-34475 , CVE-2026-50052 Description
The updated packages fix security vulnerabilities: Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. (CVE-2026-34475) In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2. HTTP/2 support is disabled by default. (CVE-2026-50052) References
SRPMS 10/core
  • varnish-8.0.2-2.mga10
9/core
  • varnish-7.7.3-1.1.mga9

MGASA-2026-0356 - Updated perl-Mojolicious packages fix a security vulnerability

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15747 Description
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. References
SRPMS 10/core
  • perl-Mojolicious-9.480.0-1.1.mga10
9/core
  • perl-Mojolicious-9.480.0-1.1.mga9

MGASA-2026-0355 - Updated vim packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-73077 , CVE-2026-73078 , CVE-2026-73074 , CVE-2026-73070 , CVE-2026-73075 , CVE-2026-73071 , CVE-2026-73073 , CVE-2026-73072 , CVE-2026-73076 Description
Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839. (CVE-2026-73077) Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840. (CVE-2026-73078) Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841. (CVE-2026-73074) Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842. (CVE-2026-73070) Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843. (CVE-2026-73075) Use-after-free in JSON Decoding in Vim >= 9.2.0511 && Vim < 9.2.0844. (CVE-2026-73071) Arbitrary Ex Command Execution in C Omni-Completion in Vim < 9.2.0845. (CVE-2026-73073) Heap Buffer Overflow when Loading a Spell File in Vim < 9.2.0846. (CVE-2026-73072) Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim`. (CVE-2026-73076) References
SRPMS 10/core
  • vim-9.2.1011-2.mga10
9/core
  • vim-9.2.1011-2.mga9

MGASA-2026-0354 - Updated redis packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62356 Description
The updated package fixes security vulnerabilities, including: Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write. (CVE-2026-62356) References
SRPMS 10/core
  • redis-8.6.6-1.mga10
9/core
  • redis-7.2.16-1.mga9

MGASA-2026-0353 - Updated openssl packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14456 , CVE-2026-18798 , CVE-2026-63072 , CVE-2026-63076 , CVE-2026-14457 , CVE-2026-54874 , CVE-2026-63073 , CVE-2026-63074 , CVE-2026-63075 , CVE-2026-75803 Description
Unbounded Memory Growth in QUIC Server Incoming Channel Queue. (CVE-2026-14456) QUIC Server May Trigger Double Free When Processing INITIAL Packet. (CVE-2026-18798) Heap Buffer Overflow in CMS Key Unwrapping. (CVE-2026-63072) Invalid Pointer Dereference in CMP Server via Crafted protectionAlg. (CVE-2026-63076) RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate. (CVE-2026-14457) Excessive Memory Use Buffering DTLS Records for a Future Epoch. (CVE-2026-54874) Untrusted Sender DN Used as Format String in CMP Response Validation. (CVE-2026-63073) CMP Indefinite Cache Growth of ExtraCerts. (CVE-2026-63074) QUIC ACK-only Packet Retention Can Cause Memory Exhaustion. (CVE-2026-63075) References
SRPMS 10/core
  • openssl-3.5.8-1.mga10
9/core
  • openssl-3.0.22-1.mga9

MGASA-2026-0352 - Updated expat & mingw-expat packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-50219 , CVE-2026-56131 , CVE-2026-56132 , CVE-2026-56403 , CVE-2026-56404 , CVE-2026-56405 , CVE-2026-56406 , CVE-2026-56407 , CVE-2026-56408 , CVE-2026-56409 , CVE-2026-56410 , CVE-2026-56411 , CVE-2026-56412 , CVE-2026-72522 Description
Missing control flow integrity checks. (CVE-2026-50219) Missing control flow integrity checks. (CVE-2026-56131) Out-of-bounds write. (CVE-2026-56132) Integer overflow. (CVE-2026-56403) Integer overflow. (CVE-2026-56404) Integer overflow. (CVE-2026-56405) Integer overflow. (CVE-2026-56406) Integer overflow. (CVE-2026-56407) Integer overflow. (CVE-2026-56408) Integer overflow. (CVE-2026-56409) Integer overflow. (CVE-2026-56410) Integer overflow. (CVE-2026-56411) Missing control flow integrity checks. (CVE-2026-56412) References
SRPMS 10/core
  • expat-2.8.3-1.mga10
  • mingw-expat-2.8.3-1.mga10

MGASA-2026-0351 - Updated perl-Catalyst-Plugin-Authentication packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2009-10007 Description
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl are susceptible to session fixation attacks. (CVE-2009-10007) References
SRPMS 10/core
  • perl-Catalyst-Plugin-Authentication-0.100.280-1.mga10
9/core
  • perl-Catalyst-Plugin-Authentication-0.100.230-12.2.mga9

MGASA-2026-0350 - Updated perl-Plack packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-7381 Description
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. References
SRPMS 10/core
  • perl-Plack-1.5.400-1.mga10
9/core
  • perl-Plack-1.5.400-1.mga9

MGASA-2026-0349 - Updated python-hpack packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-59980 Description
An issue was found in the python-hyper/hpack library, most commonly used as a downstream dependency of the python-hyper/h2 library (an HTTP/2 client and server implementation). Unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large enough unsanitized input. A fix python-hyper/hpack v4.2.0 restricts variable integer decoding to uint32 to prevent run-away computation. References
SRPMS 10/core
  • python-hpack-4.2.0-1.mga10

MGASA-2026-0348 - Updated clamav packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20345 , CVE-2026-20339 , CVE-2026-20346 , CVE-2026-20347 , CVE-2026-20348 Description
An indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. (CVE-2026-20345) An integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. (CVE-2026-20339) An integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. (CVE-2026-20346) Undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347) XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. (CVE-2026-20348) References
SRPMS 10/core
  • clamav-1.4.6-1.mga10

MGAA-2026-0117 - Updated mga-advisor package fixes bugs

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
The updated package brings improvement to our graphic tool to make advisories, the changes include but are not limited to: Ver. 6 - Choose only the Mageia versions affected by a bug - Dedupe the package names before checking package info - Allow multiple CVEs or references to be added at once - Improve duplicate CVE warnings - Expand bracket expressions in the list of CVEs - Retrieve package info in parallel for speed - Open a URL in the references by double-clicking it - Join package names in the subject with & or , - Improve the package name regex to solve problems with dots in names - Use singular form in subject with only one package or vuln - Add a status message for each package being retrieved - Fix search in release 10 for source packages Ver. 5 - Run more data checks after loading from Bugzilla - Open a URL in the references by double-clicking it - Join package names in the subject with & or , - Improve the package name regex to solve problems with dots in names - Internal refactoring & minor changes - Use singular form in subject with only one package or vuln - Add a status message for each package being retrieved - Add a timeout when reading from Bugzilla - Display the version number on-screen Ver. 4 - Increase widths of text fields in dialogs - Fix search in release 10 for source packages Ver. 3 - Add syntax checks on package name - Add whitespace checks on subject - Use slash when displaying sources - Drop mga8 as a source and replace with mga10 - Add checks for invalid CVE IDs and URL references - Send a custom User-Agent with Bugzilla requests - Internal cleanups References
SRPMS 10/core
  • mga-advisor-6-1.mga10

MGAA-2026-0116 - Updated kcalc package fixes bug

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
You can't copy and paste from the Edit menu in kcalc; it has no effect. Updated packages fixes the reported issue. References
SRPMS 10/core
  • kcalc-25.12.1-1.1.mga10

MGAA-2026-0115 - Updated krita-ai-diffusion package fixes bug

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
krita-ai-diffusion is updated to version 1.53.0 References
SRPMS 10/core
  • krita-ai-diffusion-1.53.0-1.mga10

MGASA-2026-0347 - Updated postgresql18 & postgresql15 packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 17:22
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-6464 , CVE-2026-6469 , CVE-2026-6470 , CVE-2026-6471 , CVE-2026-14662 , CVE-2026-14663 , CVE-2026-14664 , CVE-2026-14666 , CVE-2026-14668 , CVE-2026-14669 , CVE-2026-14670 , CVE-2026-14671 , CVE-2026-14672 , CVE-2026-14673 , CVE-2026-14676 , CVE-2026-14677 , CVE-2026-14678 , CVE-2026-14679 , CVE-2026-14680 , CVE-2026-14681 , CVE-2026-15741 , CVE-2026-15742 , CVE-2026-16238 , CVE-2026-16239 , CVE-2026-16241 , CVE-2026-18024 , CVE-2026-18408 , CVE-2026-19385 Description
psql COPY FROM STDIN early failure processes data lines as psql commands. (CVE-2026-6464) ALTER TABLE ALTER TYPE resets extended statistics ownership. (CVE-2026-6469) Fails to check type USAGE privilege. (CVE-2026-6470) Logical decoding can dlopen arbitrary file. (CVE-2026-6471) tsvector and tsquery undersize allocations, via integer wraparound. (CVE-2026-14662) pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext. (CVE-2026-14663) Regexp heap buffer overflow executes arbitrary code. (CVE-2026-14664) Row security caching disregards role modifications. (CVE-2026-14666) ctid type confusion in selectivity estimator discloses derivative of arbitrary read. (CVE-2026-14668) to_char heap buffer overflow executes arbitrary code. (CVE-2026-14669) plperl tied object heap buffer overflow executes arbitrary code. (CVE-2026-14670) refint plan cache type confusion executes arbitrary code. (CVE-2026-14671) Observable response discrepancy with non-default scram_iterations provides user existence oracle. (CVE-2026-14672) amcheck does not clear untrusted search path. (CVE-2026-14673) pg_stat_statements heap buffer overflow executes arbitrary code. (CVE-2026-14676) 32-bit pltcl and plperl undersize allocations, via integer wraparound. (CVE-2026-14677) pg_trgm picksplit reads past end of buffer. (CVE-2026-14678) Stack buffer overflow in argument match writes 0x0 and 0x1 to server memory. (CVE-2026-14679) Type confusion via "internal" arguments. (CVE-2026-14680) Improper enforcement of GSSAPI encryption when coupled with SSL. (CVE-2026-14681) Expression deparse allows SQL injection via EXTRACT argument. (CVE-2026-15741) fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound. (CVE-2026-15742) Type confusion in pg_restore_attribute_stats() executes arbitrary code. (CVE-2026-16238) Type confusion in cursor CLOSE + DECLARE executes arbitrary code. (CVE-2026-16239) ECPG integer underflow can crash the client. (CVE-2026-16241) ascii() function reads past end of buffer. (CVE-2026-18024) psql unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client. (CVE-2026-18408) pg_dump heap buffer overflow executes arbitrary code. (CVE-2026-19385) References
SRPMS 10/core
  • postgresql18-18.6-1.mga10
  • postgresql15-15.19-1.mga10
9/core
  • postgresql15-15.19-1.mga9

MGASA-2026-0346 - Updated thunderbird packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 17:22
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990 Description
Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74987) Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 (CVE-2026-74988) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74990) References
SRPMS 10/core
  • thunderbird-153.1.0-1.mga10
  • thunderbird-l10n-153.1.0-1.mga10
9/core
  • thunderbird-140.14.0-1.mga9
  • thunderbird-l10n-140.14.0-1.mga9

MGASA-2026-0345 - Updated nspr, nss, & firefox packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 17:22
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990 Description
Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74987) Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. (CVE-2026-74988) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74990) References
SRPMS 10/core
  • nspr-4.40.0-1.mga10
  • nss-3.127.0-1.mga10
  • firefox-153.1.0-1.mga10
  • firefox-l10n-153.1.0-1.mga10
9/core
  • nspr-4.40.0-1.mga9
  • nss-3.127.0-1.mga9
  • firefox-140.14.0-1.mga9
  • firefox-l10n-140.14.0-1.mga9
Feed