pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/www/firefox153



Module Name:    pkgsrc
Committed By:   gutteridge
Date:           Tue Sep 15 13:20:42 UTC 2026

Modified Files:
        pkgsrc/www/firefox153: Makefile distinfo

Log Message:
firefox153: update to 153.3

Mozilla Foundation Security Advisory 2026-93
Security Vulnerabilities fixed in Firefox ESR 153.3

Announced
    September 15, 2026
Impact
    high
Products
    Firefox ESR
Fixed in

        Firefox ESR 153.3

Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component

Reporter
    devdharan9424%gmail.com@localhost
Impact
    high

References

    Bug 2056051

#CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2057121

#CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2058064

#CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2058065

#CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2058066

#CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2058067

#CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2058068

#CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2058069

#CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2058078

#CVE-2026-92015: Privilege escalation in the WebExtensions component

Reporter
    Quy Pham
Impact
    high

References

    Bug 2060235

#CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component

Reporter
    Mozilla
Impact
    high

References

    Bug 2061245

#CVE-2026-92016: Use-after-free in the Disability Access APIs component

Reporter
    Mozilla
Impact
    high

References

    Bug 2061327

#CVE-2026-92017: Privilege escalation in the DOM: Service Workers component

Reporter
    Mozilla
Impact
    high

References

    Bug 2061777

#CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component

Reporter
    Quy Pham
Impact
    high

References

    Bug 2064287

#CVE-2026-92019: Mitigation bypass in the Remote Settings Client component

Reporter
    Shu Takahashi
Impact
    high

References

    Bug 2065636

#CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component

Reporter
    Rintaro Kawasugi
Impact
    high

References

    Bug 2066329

#CVE-2026-92022: Use-after-free in the DOM: HTML Parser component

Reporter
    Seohyeon Maeng
Impact
    high

References

    Bug 2068059

#CVE-2026-92023: Use-after-free in the XML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068342

#CVE-2026-92024: Use-after-free in the SVG component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068354

#CVE-2026-92025: Use-after-free in the DOM: Navigation component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068361

#CVE-2026-92026: Use-after-free in the Networking component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068378

#CVE-2026-92027: Use-after-free in the DOM: Streams component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068433

#CVE-2026-92028: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068440

#CVE-2026-92029: Use-after-free in the SVG component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068445

#CVE-2026-92038: Mitigation bypass in the Remote Settings Client component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068952

#CVE-2026-92039: Mitigation bypass in the DOM: Notifications component

Reporter
    tiebuchen
Impact
    moderate

References

    Bug 2001265

#CVE-2026-92041: Mitigation bypass in the DOM: Networking component

Reporter
    Atsushi Sada
Impact
    moderate

References

    Bug 2029482

#CVE-2026-92042: Race condition in the DOM: Content Processes component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2049342

#CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2050150

#CVE-2026-92044: Information disclosure in the Networking: HTTP component

Reporter
    Gee-netics
Impact
    moderate

References

    Bug 2051466

#CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2054622

#CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component

Reporter
    anas cherni
Impact
    moderate

References

    Bug 2058417

#CVE-2026-92046: Use-after-free in the Graphics component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2058618

#CVE-2026-92047: Privilege escalation in the Crash Reporting component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2059021

#CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2061235

#CVE-2026-92049: Use-after-free in the Widget: Win32 component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2061295

#CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2061499

#CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2061503

#CVE-2026-92054: Privilege escalation in the Memory component

Reporter
    Amy Burnett of OpenAI
Impact
    moderate

References

    Bug 2062551

#CVE-2026-92055: Privilege escalation in the DevTools component

Reporter
    Finn Westendorf
Impact
    moderate

References

    Bug 2063652

#CVE-2026-92056: Use-after-free in the Graphics: Text component

Reporter
    r00tdaddy
Impact
    moderate

References

    Bug 2065346

#CVE-2026-92057: Mitigation bypass in the Enterprise Policies component

Reporter
    Shu Takahashi
Impact
    moderate

References

    Bug 2065646

#CVE-2026-92031: Information disclosure in the Graphics: ImageLib component

Reporter
    Qi Qin
Impact
    moderate

References

    Bug 2067971

#CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2068437

#CVE-2026-92058: Use-after-free in the Graphics component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2068438

#CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2068442

#CVE-2026-92060: Use-after-free in the Internationalization component

Reporter
    Mozilla
Impact
    low

References

    Bug 2027336

#CVE-2026-92062: Privilege escalation in the Session Restore component

Reporter
    Mozilla
Impact
    low

References

    Bug 2054670

#CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Reporter
    Mozilla
Impact
    low

References

    Bug 2057990

#CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Reporter
    Mozilla
Impact
    low

References

    Bug 2058018

#CVE-2026-92067: Use-after-free in the Widget: Gtk component

Reporter
    Mozilla
Impact
    low

References

    Bug 2058664

#CVE-2026-92068: Site isolation issue in the Reader Mode component

Reporter
    Mozilla
Impact
    low

References

    Bug 2058790

#CVE-2026-92069: Spoofing issue in the DOM: Navigation component

Reporter
    Mozilla
Impact
    low

References

    Bug 2059196

#CVE-2026-92070: Information disclosure in the Networking component

Reporter
    Mohamed Mbarek
Impact
    low

References

    Bug 2060220

#CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Reporter
    Mozilla
Impact
    low

References

    Bug 2061231

#CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component

Reporter
    Mozilla
Impact
    low

References

    Bug 2061257

#CVE-2026-92073: Privilege escalation in the Enterprise Policies component

Reporter
    Tyler Maclachlan
Impact
    low

References

    Bug 2062527

#CVE-2026-92074: Mitigation bypass in the Popup Blocker component

Reporter
    Finn Westendorf
Impact
    low

References

    Bug 2063539

#CVE-2026-92075: Mitigation bypass in the Networking component

Reporter
    Takeshi Kaneko
Impact
    low

References

    Bug 2063814

#CVE-2026-92076: Incorrect boundary conditions in the Networking component

Reporter
    Mozilla
Impact
    low

References

    Bug 2064026

#CVE-2026-92077: Denial-of-service in the SVG component

Reporter
    sak
Impact
    low

References

    Bug 2064601

#CVE-2026-92078: Denial-of-service in the Security component

Reporter
    Dominik Bay
Impact
    low

References

    Bug 2066736

#CVE-2026-92079: Mitigation bypass in the Widget: Win32 component

Reporter
    barbarossa404
Impact
    low

References

    Bug 2067531


To generate a diff of this commit:
cvs rdiff -u -r1.3 -r1.4 pkgsrc/www/firefox153/Makefile
cvs rdiff -u -r1.2 -r1.3 pkgsrc/www/firefox153/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/www/firefox153/Makefile
diff -u pkgsrc/www/firefox153/Makefile:1.3 pkgsrc/www/firefox153/Makefile:1.4
--- pkgsrc/www/firefox153/Makefile:1.3  Wed Sep  2 19:04:57 2026
+++ pkgsrc/www/firefox153/Makefile      Tue Sep 15 13:20:42 2026
@@ -1,12 +1,11 @@
-# $NetBSD: Makefile,v 1.3 2026/09/02 19:04:57 wiz Exp $
+# $NetBSD: Makefile,v 1.4 2026/09/15 13:20:42 gutteridge Exp $
 
 FIREFOX_VER=           ${MOZ_BRANCH}${MOZ_BRANCH_MINOR}
-MOZ_BRANCH=            153.2
+MOZ_BRANCH=            153.3
 MOZ_BRANCH_MINOR=      .0esr
 
 DISTNAME=      firefox-${FIREFOX_VER}.source
 PKGNAME=       ${DISTNAME:S/.source//:S/b/beta/:S/esr//:S/firefox-/firefox153-/}
-PKGREVISION=   1
 CATEGORIES=    www
 MASTER_SITES+= ${MASTER_SITE_MOZILLA:=firefox/releases/${FIREFOX_VER}/source/}
 MASTER_SITES+= ${MASTER_SITE_MOZILLA_ALL:=firefox/releases/${FIREFOX_VER}/source/}

Index: pkgsrc/www/firefox153/distinfo
diff -u pkgsrc/www/firefox153/distinfo:1.2 pkgsrc/www/firefox153/distinfo:1.3
--- pkgsrc/www/firefox153/distinfo:1.2  Tue Sep  1 16:09:24 2026
+++ pkgsrc/www/firefox153/distinfo      Tue Sep 15 13:20:42 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.2 2026/09/01 16:09:24 gutteridge Exp $
+$NetBSD: distinfo,v 1.3 2026/09/15 13:20:42 gutteridge Exp $
 
-BLAKE2s (firefox-153.2.0esr.source.tar.xz) = 3457f7e0f25e3a1f39403d5b0bed9ed1b933ce3f4b098b3d8ef55417a58c42df
-SHA512 (firefox-153.2.0esr.source.tar.xz) = a8cd4784bb52ca89c0fe37404e894c044f6145c62e9fcdeffe621fde81ae4602078be575e26c90d83e5e47f26675d3ee897cd6a20027d09d4ba7d0e785ce39bc
-Size (firefox-153.2.0esr.source.tar.xz) = 807705672 bytes
+BLAKE2s (firefox-153.3.0esr.source.tar.xz) = 8e18dde67b90030e4ea0d8404e2a446e8da0bb71320d23671eb017c03ab0c6e3
+SHA512 (firefox-153.3.0esr.source.tar.xz) = 56a5e092f0aba91febf01d227e8068520513f632d09c5ffbad4cbb2de307d9066425f353a1b7fcf5648733e02a9b17cfc9aaed5e39d7562a6b143b1c9827a668
+Size (firefox-153.3.0esr.source.tar.xz) = 804997520 bytes
 BLAKE2s (nodejs-output-153.0.tgz) = 55a9ae8d1b743f57148a3b763bce2bc9afe2bd902f5b5d6a07a3e597c569aca1
 SHA512 (nodejs-output-153.0.tgz) = 2513c4c47c9bb619a1702a36b8ec316a6c48d6b641656abf86ff33c5ae9e146721947b26a3a1af8295a005daeffb0c77e5f82f36ca9a717decc6850b3518c275
 Size (nodejs-output-153.0.tgz) = 247910 bytes



Home | Main Index | Thread Index | Old Index