pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/www/firefox140



Module Name:    pkgsrc
Committed By:   gutteridge
Date:           Wed Aug 19 02:36:12 UTC 2026

Modified Files:
        pkgsrc/www/firefox140: Makefile distinfo

Log Message:
firefox140: update to 140.14

Mozilla Foundation Security Advisory 2026-76
Security Vulnerabilities fixed in Firefox ESR 140.14

Announced
    August 18, 2026
Impact
    high
Products
    Firefox ESR
Fixed in

        Firefox ESR 140.14

#CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component

Reporter
    satyamasd
Impact
    high

References

    Bug 2050584

#CVE-2026-74935: Privilege escalation in the DOM: Networking component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2051013

#CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component

Reporter
    Amy Burnett of OpenAI
Impact
    high

References

    Bug 2052688

#CVE-2026-74939: Privilege escalation in the DOM: Navigation component

Reporter
    choeseyeong
Impact
    high

References

    Bug 2054416

#CVE-2026-74940: Use-after-free in the Graphics: Text component

Reporter
    kiyong
Impact
    high

References

    Bug 2054842

#CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component

Reporter
    Jacolon Walker
Impact
    high

References

    Bug 2055056

#CVE-2026-74942: Privilege escalation in the Remote Settings Client component

Reporter
    Gal Ankonina
Impact
    high

References

    Bug 2056571

#CVE-2026-74943: Use-after-free in the Graphics: ImageLib component

Reporter
    Abdulaziz Alasaiqah
Impact
    high

References

    Bug 2057308

#CVE-2026-74944: Use-after-free in the DOM: Core & HTML component

Reporter
    Amy Burnett of OpenAI
Impact
    high

References

    Bug 2057778

#CVE-2026-74945: Information disclosure in the Graphics: Text component

Reporter
    Abdulaziz Alasaiqah
Impact
    high

References

    Bug 2057808

#CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    locust1b
Impact
    high

References

    Bug 2059997

#CVE-2026-74948: Information disclosure in the Graphics component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2060106

#CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component

Reporter
    r00tdaddy
Impact
    high

References

    Bug 2060245

#CVE-2026-74953: Privilege escalation in the Networking: Cookies component

Reporter
    Satoki Tsuji
Impact
    moderate

References

    Bug 2022382

#CVE-2026-74957: Mitigation bypass in the Safe Browsing component

Reporter
    Tomoya Nakanishi
Impact
    moderate

References

    Bug 2041906

#CVE-2026-74959: Mitigation bypass in the Storage: Cache API component

Reporter
    David Bors at Snyk Security Labs
Impact
    moderate

References

    Bug 2047853

#CVE-2026-74960: Site isolation issue in the WebExtensions component

Reporter
    Khanh Nguyen
Impact
    moderate

References

    Bug 2049148

#CVE-2026-74962: Site isolation issue in the Networking: Cookies component

Reporter
    Yaqoub Aldurayhim
Impact
    moderate

References

    Bug 2050425

#CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component

Reporter
    5up3rh3i
Impact
    moderate

References

    Bug 2050482

#CVE-2026-74964: Integer overflow in the Graphics component

Reporter
    5up3rh3i
Impact
    moderate

References

    Bug 2053327

#CVE-2026-74965: Privilege escalation in the Shell Integration component

Reporter
    Khanh Nguyen
Impact
    moderate

References

    Bug 2053455

#CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component

Reporter
    The Mozilla Fuzzing Team
Impact
    moderate

References

    Bug 2055697

#CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component

Reporter
    Hyeonjun Ahn
Impact
    moderate

References

    Bug 2056065

#CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component

Reporter
    avlidienbrunn
Impact
    moderate

References

    Bug 2057204

#CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component

Reporter
    Kagami Rosylight
Impact
    moderate

References

    Bug 2059053

#CVE-2026-74973: Race condition, use-after-free in the Graphics component

Reporter
    r00tdaddy
Impact
    moderate

References

    Bug 2060357

#CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component

Reporter
    The Mozilla Fuzzing Team
Impact
    moderate

References

    Bug 2061794

#CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component

Reporter
    anbu
Impact
    low

References

    Bug 1952164

#CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component

Reporter
    5up3rh3i
Impact
    low

References

    Bug 2051897

#CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Reporter
    Nicolas Silva, Tom Ritter and the Mozilla Fuzzing Team
Impact
    high

Description

Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that 
with enough effort some of these could have been exploited.
References

    High Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
    Moderate Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
    Low Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

#CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Reporter
    Christian Holler, Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
Impact
    high

Description

Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect 
and we presume that with enough effort some of these could have been exploited.
References

    High Severity internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
    Moderate Severity internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154


To generate a diff of this commit:
cvs rdiff -u -r1.21 -r1.22 pkgsrc/www/firefox140/Makefile
cvs rdiff -u -r1.19 -r1.20 pkgsrc/www/firefox140/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/www/firefox140/Makefile
diff -u pkgsrc/www/firefox140/Makefile:1.21 pkgsrc/www/firefox140/Makefile:1.22
--- pkgsrc/www/firefox140/Makefile:1.21 Tue Jul 21 16:30:32 2026
+++ pkgsrc/www/firefox140/Makefile      Wed Aug 19 02:36:12 2026
@@ -1,7 +1,7 @@
-# $NetBSD: Makefile,v 1.21 2026/07/21 16:30:32 gutteridge Exp $
+# $NetBSD: Makefile,v 1.22 2026/08/19 02:36:12 gutteridge Exp $
 
 FIREFOX_VER=           ${MOZ_BRANCH}${MOZ_BRANCH_MINOR}
-MOZ_BRANCH=            140.13
+MOZ_BRANCH=            140.14
 MOZ_BRANCH_MINOR=      .0esr
 
 DISTNAME=      firefox-${FIREFOX_VER}.source

Index: pkgsrc/www/firefox140/distinfo
diff -u pkgsrc/www/firefox140/distinfo:1.19 pkgsrc/www/firefox140/distinfo:1.20
--- pkgsrc/www/firefox140/distinfo:1.19 Tue Jul 21 16:30:32 2026
+++ pkgsrc/www/firefox140/distinfo      Wed Aug 19 02:36:12 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.19 2026/07/21 16:30:32 gutteridge Exp $
+$NetBSD: distinfo,v 1.20 2026/08/19 02:36:12 gutteridge Exp $
 
-BLAKE2s (firefox-140.13.0esr.source.tar.xz) = ea85681fc369dc74f8637b1182840a2c3be8dc94bfbb5666e7bf53f46625cf9e
-SHA512 (firefox-140.13.0esr.source.tar.xz) = 937a4103d71c5e1e4bf051821729f6ea70b5c18d444930a487695cc23d74712a0134047248f6ac02305e01becb705426a55b9d89739f02a01eda01ecf5bc27f1
-Size (firefox-140.13.0esr.source.tar.xz) = 644768324 bytes
+BLAKE2s (firefox-140.14.0esr.source.tar.xz) = 6e444488cfb0cd6c0ec8dbcc7328916fcf2b9ef09ec327886a7116cd3a7c54cb
+SHA512 (firefox-140.14.0esr.source.tar.xz) = 0609cca9bfaecbff56cdf13458534bd8cfa43f139056867d3b6394a767281599ee600f83165ad25565ced59b552592aa84431357458ccecfbe5bf104dca501c7
+Size (firefox-140.14.0esr.source.tar.xz) = 643083928 bytes
 BLAKE2s (nodejs-output-140.0.4.tgz) = 7ebb5993c8c9d7d5492afdb9fa7fef74fec7753fb0b14673817f24faf4a7fca4
 SHA512 (nodejs-output-140.0.4.tgz) = e421b0b6be8b5b8dfda705eefcf4573a1270df9012dca5eac9ba0ac2af2bcc47dd66b1057106f8c2336a10bdcc39b9f852041dd33da9e7a8929d981dbb4e1fb4
 Size (nodejs-output-140.0.4.tgz) = 245385 bytes



Home | Main Index | Thread Index | Old Index