pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/www/firefox153



Module Name:    pkgsrc
Committed By:   gutteridge
Date:           Tue Sep 29 13:03:44 UTC 2026

Modified Files:
        pkgsrc/www/firefox153: Makefile distinfo
        pkgsrc/www/firefox153/patches:
            patch-toolkit_components_terminator_nsTerminator.cpp

Log Message:
firefox153: update to 153.4

Mozilla Foundation Security Advisory 2026-100
Security Vulnerabilities fixed in Firefox ESR 153.4

Announced
    September 29, 2026
Impact
    high
Products
    Firefox ESR
Fixed in

        Firefox ESR 153.4

Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component

Reporter
    Mozilla
Impact
    high

References

    Bug 2047721

#CVE-2026-100757: Use-after-free in the Widget component

Reporter
    Mohamed Mbarek
Impact
    high

References

    Bug 2049352

#CVE-2026-100758: Sandbox escape in the DOM: Navigation component

Reporter
    Mozilla
Impact
    high

References

    Bug 2049792

#CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager component

Reporter
    Mozilla
Impact
    high

References

    Bug 2054736

#CVE-2026-100760: Sandbox escape in the Security: Process Sandboxing component

Reporter
    Mozilla
Impact
    high

References

    Bug 2058017

#CVE-2026-100762: Sandbox escape due to use-after-free in the DOM: Content Processes component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2059404

#CVE-2026-100765: Use-after-free in the JavaScript: WebAssembly component

Reporter
    Mozilla
Impact
    high

References

    Bug 2061399

#CVE-2026-100766: Information disclosure in the Networking: JAR component

Reporter
    Mozilla
Impact
    high

References

    Bug 2061526

#CVE-2026-100767: Use-after-free in the Networking: Cache component

Reporter
    Mozilla
Impact
    high

References

    Bug 2063680

#CVE-2026-100769: Use-after-free in the JavaScript: WebAssembly component

Reporter
    Tomer Fichman
Impact
    high

References

    Bug 2067190

#CVE-2026-100770: Sandbox escape due to use-after-free in the DOM: Content Processes component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068322

#CVE-2026-100771: Undefined behavior in the DOM: Streams component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068336

#CVE-2026-100772: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068340

#CVE-2026-100773: Use-after-free in the Storage: IndexedDB component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068346

#CVE-2026-100774: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068351

#CVE-2026-100775: Sandbox escape in the Graphics component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068367

#CVE-2026-100776: Use-after-free in the JavaScript: WebAssembly component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068374

#CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068375

#CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068406

#CVE-2026-100779: Use-after-free in the XSLT component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068417

#CVE-2026-100780: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068422

#CVE-2026-100781: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068434

#CVE-2026-100782: Privilege escalation due to incorrect boundary conditions in the Graphics component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068456

#CVE-2026-100783: Uninitialized memory in the Audio/Video component

Reporter
    5up3rh3i
Impact
    high

References

    Bug 2069804

#CVE-2026-100784: Use-after-free in the Layout: Text and Fonts component

Reporter
    5up3rh3i
Impact
    high

References

    Bug 2070264

#CVE-2026-100785: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2071064

#CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics component

Reporter
    Mozilla
Impact
    high

References

    Bug 2071067

#CVE-2026-100787: Sandbox escape in the XUL component

Reporter
    Mozilla
Impact
    high

References

    Bug 2071068

#CVE-2026-100788: Invalid pointer in the JavaScript: WebAssembly component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072413

#CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072429

#CVE-2026-100790: Use-after-free in the XSLT component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072432

#CVE-2026-100791: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072433

#CVE-2026-100832: Use-after-free in the Graphics: Canvas2D component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072467

#CVE-2026-100792: JIT miscompilation in the JavaScript: WebAssembly component

Reporter
    Amy Burnett of OpenAI
Impact
    high

References

    Bug 2073266

#CVE-2026-100794: Sandbox escape due to incorrect boundary conditions in the Internationalization component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2028871

#CVE-2026-96869: Information disclosure in the Networking component

Reporter
    Carlo Di Dato
Impact
    moderate

References

    Bug 2041248

#CVE-2026-100797: Privilege escalation due to use-after-free in the Graphics: WebRender component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2050542

#CVE-2026-100798: Cryptography misuse in Storage: Quota Manager component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2055694

#CVE-2026-100800: Sandbox escape due to use-after-free in the Disability Access APIs component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2056767

#CVE-2026-100801: Privilege escalation in the DLL Services component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2057112

#CVE-2026-100803: Same-origin policy bypass in the WebExtensions component

Reporter
    Yaqoub Aldurayhim
Impact
    moderate

References

    Bug 2057988

#CVE-2026-100806: Uninitialized memory in the Graphics: WebGPU component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2060408

#CVE-2026-100807: Privilege escalation in the DOM: Service Workers component

Reporter
    Khanh Nguyen
Impact
    moderate

References

    Bug 2062740

#CVE-2026-100808: Mitigation bypass in the DOM: Service Workers component

Reporter
    WinD39
Impact
    moderate

References

    Bug 2063488

#CVE-2026-100809: Same-origin policy bypass in the DevTools component

Reporter
    Finn Westendorf
Impact
    moderate

References

    Bug 2063658

#CVE-2026-100811: Sandbox escape due to use-after-free in the DOM: Core & HTML component

Reporter
    Yaqoub Aldurayhim
Impact
    moderate

References

    Bug 2067973

#CVE-2026-100812: Denial-of-service in the Graphics component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2068335

#CVE-2026-100814: Incorrect boundary conditions in the JavaScript Engine: JIT component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2068385

#CVE-2026-100815: Use-after-free in the CSS Parsing and Computation component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2068404

#CVE-2026-100816: Site isolation issue in the DOM: Networking component

Reporter
    Rintaro Kawasugi
Impact
    moderate

References

    Bug 2068648

#CVE-2026-100818: Sandbox escape due to use-after-free in the Widget: Gtk component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2069399

#CVE-2026-100819: Sandbox escape due to incorrect boundary conditions in the XPCOM component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2071069

#CVE-2026-100820: Privilege escalation in the Address Bar component

Reporter
    Tran Quac
Impact
    moderate

References

    Bug 2071645

#CVE-2026-100821: Site isolation issue in the Panning and Zooming component

Reporter
    Nguyen Thanh Nguyen
Impact
    moderate

References

    Bug 2071784

#CVE-2026-100822: Spoofing issue in the Networking: HTTP component

Reporter
    Tomoya Nakanishi
Impact
    low

References

    Bug 2051115

#CVE-2026-100824: Privilege escalation in the Places component

Reporter
    Mozilla
Impact
    low

References

    Bug 2054767

#CVE-2026-100825: Use-after-free in the JavaScript Engine: JIT component

Reporter
    x0e
Impact
    low

References

    Bug 2057465

#CVE-2026-100826: Denial-of-service in the Storage: StorageManager component

Reporter
    Mozilla
Impact
    low

References

    Bug 2059222

#CVE-2026-100828: Mitigation bypass in the Bookmarks & History component

Reporter
    Rintaro Kawasugi
Impact
    low

References

    Bug 2066019

#CVE-2026-100829: Mitigation bypass in the DOM: Security component

Reporter
    Rintaro Kawasugi
Impact
    low

References

    Bug 2066321

#CVE-2026-100830: Mitigation bypass in the DOM: Navigation component

Reporter
    Finn Westendorf
Impact
    low

References

    Bug 2066770

#CVE-2026-100831: Use-after-free in the DOM: UI Events & Focus Handling component

Reporter
    Mozilla
Impact
    low

References

    Bug 2067172


To generate a diff of this commit:
cvs rdiff -u -r1.6 -r1.7 pkgsrc/www/firefox153/Makefile
cvs rdiff -u -r1.3 -r1.4 pkgsrc/www/firefox153/distinfo
cvs rdiff -u -r1.1 -r1.2 \
    pkgsrc/www/firefox153/patches/patch-toolkit_components_terminator_nsTerminator.cpp

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/www/firefox153/Makefile
diff -u pkgsrc/www/firefox153/Makefile:1.6 pkgsrc/www/firefox153/Makefile:1.7
--- pkgsrc/www/firefox153/Makefile:1.6  Tue Sep 29 06:08:04 2026
+++ pkgsrc/www/firefox153/Makefile      Tue Sep 29 13:03:44 2026
@@ -1,12 +1,11 @@
-# $NetBSD: Makefile,v 1.6 2026/09/29 06:08:04 wiz Exp $
+# $NetBSD: Makefile,v 1.7 2026/09/29 13:03:44 gutteridge Exp $
 
 FIREFOX_VER=           ${MOZ_BRANCH}${MOZ_BRANCH_MINOR}
-MOZ_BRANCH=            153.3
+MOZ_BRANCH=            153.4
 MOZ_BRANCH_MINOR=      .0esr
 
 DISTNAME=      firefox-${FIREFOX_VER}.source
 PKGNAME=       ${DISTNAME:S/.source//:S/b/beta/:S/esr//:S/firefox-/firefox153-/}
-PKGREVISION=   2
 CATEGORIES=    www
 MASTER_SITES+= ${MASTER_SITE_MOZILLA:=firefox/releases/${FIREFOX_VER}/source/}
 MASTER_SITES+= ${MASTER_SITE_MOZILLA_ALL:=firefox/releases/${FIREFOX_VER}/source/}

Index: pkgsrc/www/firefox153/distinfo
diff -u pkgsrc/www/firefox153/distinfo:1.3 pkgsrc/www/firefox153/distinfo:1.4
--- pkgsrc/www/firefox153/distinfo:1.3  Tue Sep 15 13:20:42 2026
+++ pkgsrc/www/firefox153/distinfo      Tue Sep 29 13:03:44 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.3 2026/09/15 13:20:42 gutteridge Exp $
+$NetBSD: distinfo,v 1.4 2026/09/29 13:03:44 gutteridge Exp $
 
-BLAKE2s (firefox-153.3.0esr.source.tar.xz) = 8e18dde67b90030e4ea0d8404e2a446e8da0bb71320d23671eb017c03ab0c6e3
-SHA512 (firefox-153.3.0esr.source.tar.xz) = 56a5e092f0aba91febf01d227e8068520513f632d09c5ffbad4cbb2de307d9066425f353a1b7fcf5648733e02a9b17cfc9aaed5e39d7562a6b143b1c9827a668
-Size (firefox-153.3.0esr.source.tar.xz) = 804997520 bytes
+BLAKE2s (firefox-153.4.0esr.source.tar.xz) = 5cff0c4b06a94dcd63b0ef203d1e47b29c6399a0fe15e20dfc882eb0bb60bca8
+SHA512 (firefox-153.4.0esr.source.tar.xz) = 79e1f2a0f8c4d156c80b8f4c580aa944600d49cc811f961a3eca251113241638991fda94ccb74a44df9030f643586c41686861333288f13793e621a262a1b131
+Size (firefox-153.4.0esr.source.tar.xz) = 801731048 bytes
 BLAKE2s (nodejs-output-153.0.tgz) = 55a9ae8d1b743f57148a3b763bce2bc9afe2bd902f5b5d6a07a3e597c569aca1
 SHA512 (nodejs-output-153.0.tgz) = 2513c4c47c9bb619a1702a36b8ec316a6c48d6b641656abf86ff33c5ae9e146721947b26a3a1af8295a005daeffb0c77e5f82f36ca9a717decc6850b3518c275
 Size (nodejs-output-153.0.tgz) = 247910 bytes
@@ -62,7 +62,7 @@ SHA1 (patch-third__party_sqlite3_ext_moz
 SHA1 (patch-third__party_sqlite3_src_moz.build) = b26856a4b87aa12211575d9982f62dc899474b52
 SHA1 (patch-third__party_wasm2c_src_c-writer.cc) = 38eb2ee0e00722aa1380540b83648b43723719aa
 SHA1 (patch-third__party_wasm2c_src_prebuilt_wasm2c__source__includes.cc) = 99d0db944f0c2d0c623460991efd423d9127c988
-SHA1 (patch-toolkit_components_terminator_nsTerminator.cpp) = e905e38ef1b88d764c695c019f15609350c1c43b
+SHA1 (patch-toolkit_components_terminator_nsTerminator.cpp) = 5fec8a65fb5528f97fc7da863fbf950f4bc25597
 SHA1 (patch-toolkit_moz.configure) = 1306e7ac3c3939886aff38a58dd3162e6517409b
 SHA1 (patch-toolkit_mozapps_installer_packager.mk) = c77481a1f8fe1e237b7fe87e3e586ca886ac1d3d
 SHA1 (patch-xpcom_base_nscore.h) = 1ac4d34d3c9e80bc1ac966c6c84cb320bc0fa1ec

Index: pkgsrc/www/firefox153/patches/patch-toolkit_components_terminator_nsTerminator.cpp
diff -u pkgsrc/www/firefox153/patches/patch-toolkit_components_terminator_nsTerminator.cpp:1.1 pkgsrc/www/firefox153/patches/patch-toolkit_components_terminator_nsTerminator.cpp:1.2
--- pkgsrc/www/firefox153/patches/patch-toolkit_components_terminator_nsTerminator.cpp:1.1      Thu Aug 27 01:23:17 2026
+++ pkgsrc/www/firefox153/patches/patch-toolkit_components_terminator_nsTerminator.cpp  Tue Sep 29 13:03:44 2026
@@ -1,10 +1,10 @@
-$NetBSD: patch-toolkit_components_terminator_nsTerminator.cpp,v 1.1 2026/08/27 01:23:17 gutteridge Exp $
+$NetBSD: patch-toolkit_components_terminator_nsTerminator.cpp,v 1.2 2026/09/29 13:03:44 gutteridge Exp $
 
 * Fix segfault on exit under NetBSD
 
---- toolkit/components/terminator/nsTerminator.cpp.orig        2022-06-16 21:35:58.000000000 +0000
+--- toolkit/components/terminator/nsTerminator.cpp.orig        2026-09-23 09:34:40.000000000 +0000
 +++ toolkit/components/terminator/nsTerminator.cpp
-@@ -34,7 +34,7 @@
+@@ -33,7 +33,7 @@
  #if defined(XP_WIN)
  #  include <windows.h>
  #else
@@ -13,7 +13,7 @@ $NetBSD: patch-toolkit_components_termin
  #endif
  
  #include "mozilla/AppShutdown.h"
-@@ -184,7 +184,10 @@ void RunWatchdog(void* arg) {
+@@ -222,7 +222,10 @@ void RunWatchdog(void*) {
  #if defined(XP_WIN)
      Sleep(HEARTBEAT_INTERVAL_MS /* ms */);
  #else
@@ -24,4 +24,4 @@ $NetBSD: patch-toolkit_components_termin
 +    nanosleep(&tickd, NULL);
  #endif
  
-     if (gHeartbeat++ < timeToLive) {
+     if (gHeartbeat++ < gCrashAfterTicks) {



Home | Main Index | Thread Index | Old Index