Security update for MozillaFirefox
| Announcement ID: | SUSE-SU-2026:1649-1 |
|---|---|
| Release Date: | 2026-04-28T18:52:37Z |
| Rating: | important |
| References: | |
| Cross-References: |
|
| CVSS scores: |
|
| Affected Products: |
|
An update that solves 25 vulnerabilities can now be installed.
Description:
This update for MozillaFirefox fixes the following issue:
Update to Firefox Extended Support Release 140.10.0 ESR (bsc#1262230, MFSA 2026-32):
- CVE-2026-6746: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-6747: Use-after-free in the WebRTC component.
- CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component.
- CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component.
- CVE-2026-6750: Privilege escalation in the Graphics: WebRender component.
- CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component.
- CVE-2026-6752: Incorrect boundary conditions in the WebRTC component.
- CVE-2026-6753: Incorrect boundary conditions in the WebRTC component.
- CVE-2026-6754: Use-after-free in the JavaScript Engine component.
- CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component.
- CVE-2026-6759: Use-after-free in the Widget: Cocoa component.
- CVE-2026-6761: Privilege escalation in the Networking component.
- CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component.
- CVE-2026-6763: Mitigation bypass in the File Handling component.
- CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component.
- CVE-2026-6765: Information disclosure in the Form Autofill component.
- CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS.
- CVE-2026-6767: Other issue in the Libraries component in NSS.
- CVE-2026-6769: Privilege escalation in the Debugger component.
- CVE-2026-6770: Other issue in the Storage: IndexedDB component.
- CVE-2026-6771: Mitigation bypass in the DOM: Security component.
- CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS.
- CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component.
- CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150.
- CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1649=1 -
Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1649=1 -
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1649=1 -
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1649=1 -
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1649=1 -
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1649=1 -
SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1649=1 -
SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1649=1 -
SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1649=1 -
SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1649=1 -
SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1649=1
Package List:
-
SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
Desktop Applications Module 15-SP7 (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
- MozillaFirefox-translations-other-140.10.0-150200.152.231.1
- MozillaFirefox-140.10.0-150200.152.231.1
- MozillaFirefox-debugsource-140.10.0-150200.152.231.1
- MozillaFirefox-translations-common-140.10.0-150200.152.231.1
- MozillaFirefox-debuginfo-140.10.0-150200.152.231.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
- MozillaFirefox-devel-140.10.0-150200.152.231.1
References:
- https://www.suse.com/security/cve/CVE-2026-6746.html
- https://www.suse.com/security/cve/CVE-2026-6747.html
- https://www.suse.com/security/cve/CVE-2026-6748.html
- https://www.suse.com/security/cve/CVE-2026-6749.html
- https://www.suse.com/security/cve/CVE-2026-6750.html
- https://www.suse.com/security/cve/CVE-2026-6751.html
- https://www.suse.com/security/cve/CVE-2026-6752.html
- https://www.suse.com/security/cve/CVE-2026-6753.html
- https://www.suse.com/security/cve/CVE-2026-6754.html
- https://www.suse.com/security/cve/CVE-2026-6757.html
- https://www.suse.com/security/cve/CVE-2026-6759.html
- https://www.suse.com/security/cve/CVE-2026-6761.html
- https://www.suse.com/security/cve/CVE-2026-6762.html
- https://www.suse.com/security/cve/CVE-2026-6763.html
- https://www.suse.com/security/cve/CVE-2026-6764.html
- https://www.suse.com/security/cve/CVE-2026-6765.html
- https://www.suse.com/security/cve/CVE-2026-6766.html
- https://www.suse.com/security/cve/CVE-2026-6767.html
- https://www.suse.com/security/cve/CVE-2026-6769.html
- https://www.suse.com/security/cve/CVE-2026-6770.html
- https://www.suse.com/security/cve/CVE-2026-6771.html
- https://www.suse.com/security/cve/CVE-2026-6772.html
- https://www.suse.com/security/cve/CVE-2026-6776.html
- https://www.suse.com/security/cve/CVE-2026-6785.html
- https://www.suse.com/security/cve/CVE-2026-6786.html
- https://bugzilla.suse.com/show_bug.cgi?id=1262230