{"id":"ECHO-f542-a708-8974","summary":"Heap buffer overflow in libvpx. Debian's firefox-esr links against the system\nlibvpx (libvpx9), not the bundled copy in the source tree. The system libvpx in\ntrixie (1.15.0-2.1+deb13u1) already includes the fix via DSA-6143-1.\nThe Debian security tracker even notes: \"Firefox, Firefox ESR and Thunderbird\nuse the system libvpx library\".\nhttps://security-tracker.debian.org/tracker/CVE-2026-2447\n","modified":"2026-09-15T00:47:47.370229138Z","published":"2026-03-17T12:30:04.167Z","withdrawn":"2026-03-17T12:30:04.167Z","upstream":["CVE-2026-2447"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-2447"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2447"},{"type":"WEB","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2014390"},{"type":"WEB","url":"https://www.mozilla.org/security/advisories/mfsa2026-10/"},{"type":"WEB","url":"https://www.mozilla.org/security/advisories/mfsa2026-11/"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/02/msg00028.html"}],"affected":[{"package":{"name":"firefox-esr","ecosystem":"Echo","purl":"pkg:deb/echo/firefox-esr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.8.0esr-1~deb13u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-f542-a708-8974.json"}}],"schema_version":"1.9.0"}