{"id":"openSUSE-SU-2026:21980-1","summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following issues:\n\nUpdate to Firefox Extended Support Release 153.4.0 ESR (MFSA 2026-100, bsc#1282929):\n\n- CVE-2026-96869: Information disclosure in the Networking component.\n- CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component.\n- CVE-2026-100757: Use-after-free in the Widget component.\n- CVE-2026-100758: Sandbox escape in the DOM: Navigation component.\n- CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager component.\n- CVE-2026-100760: Sandbox escape in the Security: Process Sandboxing component.\n- CVE-2026-100762: Sandbox escape due to use-after-free in the DOM: Content Processes component.\n- CVE-2026-100765: Use-after-free in the JavaScript: WebAssembly component.\n- CVE-2026-100766: Information disclosure in the Networking: JAR component.\n- CVE-2026-100767: Use-after-free in the Networking: Cache component.\n- CVE-2026-100769: Use-after-free in the JavaScript: WebAssembly component.\n- CVE-2026-100770: Sandbox escape due to use-after-free in the DOM: Content Processes component.\n- CVE-2026-100771: Undefined behavior in the DOM: Streams component.\n- CVE-2026-100772: Use-after-free in the DOM: Core & HTML component.\n- CVE-2026-100773: Use-after-free in the Storage: IndexedDB component.\n- CVE-2026-100774: Use-after-free in the DOM: Core & HTML component.\n- CVE-2026-100775: Sandbox escape in the Graphics component.\n- CVE-2026-100776: Use-after-free in the JavaScript: WebAssembly component.\n- CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component.\n- CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core & HTML component.\n- CVE-2026-100779: Use-after-free in the XSLT component.\n- CVE-2026-100780: Use-after-free in the DOM: Core & HTML component.\n- CVE-2026-100781: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component.\n- CVE-2026-100782: Privilege escalation due to incorrect boundary conditions in the Graphics component.\n- CVE-2026-100783: Uninitialized memory in the Audio/Video component.\n- CVE-2026-100784: Use-after-free in the Layout: Text and Fonts component.\n- CVE-2026-100785: Use-after-free in the DOM: Core & HTML component.\n- CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics component.\n- CVE-2026-100787: Sandbox escape in the XUL component.\n- CVE-2026-100788: Invalid pointer in the JavaScript: WebAssembly component.\n- CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component.\n- CVE-2026-100790: Use-after-free in the XSLT component.\n- CVE-2026-100791: Use-after-free in the DOM: Core & HTML component.\n- CVE-2026-100792: JIT miscompilation in the JavaScript: WebAssembly component.\n- CVE-2026-100794: Sandbox escape due to incorrect boundary conditions in the Internationalization component.\n- CVE-2026-100797: Privilege escalation due to use-after-free in the Graphics: WebRender component.\n- CVE-2026-100798: Cryptography misuse in Storage: Quota Manager component.\n- CVE-2026-100800: Sandbox escape due to use-after-free in the Disability Access APIs component.\n- CVE-2026-100801: Privilege escalation in the DLL Services component.\n- CVE-2026-100803: Same-origin policy bypass in the WebExtensions component.\n- CVE-2026-100806: Uninitialized memory in the Graphics: WebGPU component.\n- CVE-2026-100807: Privilege escalation in the DOM: Service Workers component.\n- CVE-2026-100808: Mitigation bypass in the DOM: Service Workers component.\n- CVE-2026-100809: Same-origin policy bypass in the DevTools component.\n- CVE-2026-100811: Sandbox escape due to use-after-free in the DOM: Core & HTML component.\n- CVE-2026-100812: Denial-of-service in the Graphics component.\n- CVE-2026-100814: Incorrect boundary conditions in the JavaScript Engine: JIT component.\n- CVE-2026-100815: Use-after-free in the CSS Parsing and Computation component.\n- CVE-2026-100816: Site isolation issue in the DOM: Networking component.\n- CVE-2026-100818: Sandbox escape due to use-after-free in the Widget: Gtk component.\n- CVE-2026-100819: Sandbox escape due to incorrect boundary conditions in the XPCOM component.\n- CVE-2026-100820: Privilege escalation in the Address Bar component.\n- CVE-2026-100821: Site isolation issue in the Panning and Zooming component.\n- CVE-2026-100822: Spoofing issue in the Networking: HTTP component.\n- CVE-2026-100824: Privilege escalation in the Places component.\n- CVE-2026-100825: Use-after-free in the JavaScript Engine: JIT component.\n- CVE-2026-100826: Denial-of-service in the Storage: StorageManager component.\n- CVE-2026-100828: Mitigation bypass in the Bookmarks & History component.\n- CVE-2026-100829: Mitigation bypass in the DOM: Security component.\n- CVE-2026-100830: Mitigation bypass in the DOM: Navigation component.\n- CVE-2026-100831: Use-after-free in the DOM: UI Events & Focus Handling component.\n- CVE-2026-100832: Use-after-free in the Graphics: Canvas2D component.\n","modified":"2026-10-01T18:23:34.538465665Z","published":"2026-09-30T13:07:26Z","related":["CVE-2026-100756","CVE-2026-100757","CVE-2026-100758","CVE-2026-100759","CVE-2026-100760","CVE-2026-100762","CVE-2026-100765","CVE-2026-100766","CVE-2026-100767","CVE-2026-100769","CVE-2026-100770","CVE-2026-100771","CVE-2026-100772","CVE-2026-100773","CVE-2026-100774","CVE-2026-100775","CVE-2026-100776","CVE-2026-100777","CVE-2026-100778","CVE-2026-100779","CVE-2026-100780","CVE-2026-100781","CVE-2026-100782","CVE-2026-100783","CVE-2026-100784","CVE-2026-100785","CVE-2026-100786","CVE-2026-100787","CVE-2026-100788","CVE-2026-100789","CVE-2026-100790","CVE-2026-100791","CVE-2026-100792","CVE-2026-100794","CVE-2026-100797","CVE-2026-100798","CVE-2026-100800","CVE-2026-100801","CVE-2026-100803","CVE-2026-100806","CVE-2026-100807","CVE-2026-100808","CVE-2026-100809","CVE-2026-100811","CVE-2026-100812","CVE-2026-100814","CVE-2026-100815","CVE-2026-100816","CVE-2026-100818","CVE-2026-100819","CVE-2026-100820","CVE-2026-100821","CVE-2026-100822","CVE-2026-100824","CVE-2026-100825","CVE-2026-100826","CVE-2026-100828","CVE-2026-100829","CVE-2026-100830","CVE-2026-100831","CVE-2026-100832","CVE-2026-96869"],"upstream":["CVE-2026-100756","CVE-2026-100757","CVE-2026-100758","CVE-2026-100759","CVE-2026-100760","CVE-2026-100762","CVE-2026-100765","CVE-2026-100766","CVE-2026-100767","CVE-2026-100769","CVE-2026-100770","CVE-2026-100771","CVE-2026-100772","CVE-2026-100773","CVE-2026-100774","CVE-2026-100775","CVE-2026-100776","CVE-2026-100777","CVE-2026-100778","CVE-2026-100779","CVE-2026-100780","CVE-2026-100781","CVE-2026-100782","CVE-2026-100783","CVE-2026-100784","CVE-2026-100785","CVE-2026-100786","CVE-2026-100787","CVE-2026-100788","CVE-2026-100789","CVE-2026-100790","CVE-2026-100791","CVE-2026-100792","CVE-2026-100794","CVE-2026-100797","CVE-2026-100798","CVE-2026-100800","CVE-2026-100801","CVE-2026-100803","CVE-2026-100806","CVE-2026-100807","CVE-2026-100808","CVE-2026-100809","CVE-2026-100811","CVE-2026-100812","CVE-2026-100814","CVE-2026-100815","CVE-2026-100816","CVE-2026-100818","CVE-2026-100819","CVE-2026-100820","CVE-2026-100821","CVE-2026-100822","CVE-2026-100824","CVE-2026-100825","CVE-2026-100826","CVE-2026-100828","CVE-2026-100829","CVE-2026-100830","CVE-2026-100831","CVE-2026-100832","CVE-2026-96869"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282929"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100756"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100757"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100758"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100759"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100760"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100762"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100765"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100766"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100767"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100769"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100770"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100771"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100772"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100773"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100775"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100776"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100777"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100778"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100779"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100780"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100781"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100782"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100783"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100784"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100787"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100789"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100792"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100794"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100797"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100798"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100800"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100801"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100803"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100806"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100807"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100808"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100809"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100811"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100812"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100815"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100819"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100820"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100822"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100824"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100825"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100826"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100828"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-100832"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-96869"}],"affected":[{"package":{"name":"MozillaFirefox","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.4.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"153.4.0-160000.1.1","MozillaFirefox":"153.4.0-160000.1.1","MozillaFirefox-branding-upstream":"153.4.0-160000.1.1","MozillaFirefox-devel":"153.4.0-160000.1.1","MozillaFirefox-translations-common":"153.4.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21980-1.json"}}],"schema_version":"1.9.0"}