pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/www/firefox140



Module Name:    pkgsrc
Committed By:   gutteridge
Date:           Tue Sep 29 13:19:11 UTC 2026

Modified Files:
        pkgsrc/www/firefox140: Makefile distinfo

Log Message:
firefox140: update to 140.17

Mozilla Foundation Security Advisory 2026-99
Security Vulnerabilities fixed in Firefox ESR 140.17

Announced
    September 29, 2026
Impact
    high
Products
    Firefox ESR
Fixed in

        Firefox ESR 140.17

Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component

Reporter
    Mozilla
Impact
    high

References

    Bug 2047721

#CVE-2026-100757: Use-after-free in the Widget component

Reporter
    Mohamed Mbarek
Impact
    high

References

    Bug 2049352

#CVE-2026-100758: Sandbox escape in the DOM: Navigation component

Reporter
    Mozilla
Impact
    high

References

    Bug 2049792

#CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager component

Reporter
    Mozilla
Impact
    high

References

    Bug 2054736

#CVE-2026-100762: Sandbox escape due to use-after-free in the DOM: Content Processes component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2059404

#CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component

Reporter
    Mozilla
Impact
    high

References

    Bug 2061245

#CVE-2026-100766: Information disclosure in the Networking: JAR component

Reporter
    Mozilla
Impact
    high

References

    Bug 2061526

#CVE-2026-100767: Use-after-free in the Networking: Cache component

Reporter
    Mozilla
Impact
    high

References

    Bug 2063680

#CVE-2026-100769: Use-after-free in the JavaScript: WebAssembly component

Reporter
    Tomer Fichman
Impact
    high

References

    Bug 2067190

#CVE-2026-100770: Sandbox escape due to use-after-free in the DOM: Content Processes component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068322

#CVE-2026-100771: Undefined behavior in the DOM: Streams component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068336

#CVE-2026-100772: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068340

#CVE-2026-100773: Use-after-free in the Storage: IndexedDB component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068346

#CVE-2026-100774: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068351

#CVE-2026-100775: Sandbox escape in the Graphics component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068367

#CVE-2026-100776: Use-after-free in the JavaScript: WebAssembly component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068374

#CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068375

#CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068406

#CVE-2026-100779: Use-after-free in the XSLT component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068417

#CVE-2026-100780: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068422

#CVE-2026-100781: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068434

#CVE-2026-100782: Privilege escalation due to incorrect boundary conditions in the Graphics component

Reporter
    Mozilla
Impact
    high

References

    Bug 2068456

#CVE-2026-100783: Uninitialized memory in the Audio/Video component

Reporter
    5up3rh3i
Impact
    high

References

    Bug 2069804

#CVE-2026-100784: Use-after-free in the Layout: Text and Fonts component

Reporter
    5up3rh3i
Impact
    high

References

    Bug 2070264

#CVE-2026-100785: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2071064

#CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics component

Reporter
    Mozilla
Impact
    high

References

    Bug 2071067

#CVE-2026-100788: Invalid pointer in the JavaScript: WebAssembly component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072413

#CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072429

#CVE-2026-100790: Use-after-free in the XSLT component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072432

#CVE-2026-100791: Use-after-free in the DOM: Core & HTML component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072433

#CVE-2026-100832: Use-after-free in the Graphics: Canvas2D component

Reporter
    Mozilla
Impact
    high

References

    Bug 2072467

#CVE-2026-100792: JIT miscompilation in the JavaScript: WebAssembly component

Reporter
    Amy Burnett of OpenAI
Impact
    high

References

    Bug 2073266

#CVE-2026-100794: Sandbox escape due to incorrect boundary conditions in the Internationalization component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2028871

#CVE-2026-96869: Information disclosure in the Networking component

Reporter
    Carlo Di Dato
Impact
    moderate

References

    Bug 2041248

#CVE-2026-100797: Privilege escalation due to use-after-free in the Graphics: WebRender component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2050542

#CVE-2026-100801: Privilege escalation in the DLL Services component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2057112

#CVE-2026-100803: Same-origin policy bypass in the WebExtensions component

Reporter
    Yaqoub Aldurayhim
Impact
    moderate

References

    Bug 2057988

#CVE-2026-100807: Privilege escalation in the DOM: Service Workers component

Reporter
    Khanh Nguyen
Impact
    moderate

References

    Bug 2062740

#CVE-2026-100811: Sandbox escape due to use-after-free in the DOM: Core & HTML component

Reporter
    Yaqoub Aldurayhim
Impact
    moderate

References

    Bug 2067973

#CVE-2026-100818: Sandbox escape due to use-after-free in the Widget: Gtk component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2069399

#CVE-2026-100819: Sandbox escape due to incorrect boundary conditions in the XPCOM component

Reporter
    Mozilla
Impact
    moderate

References

    Bug 2071069

#CVE-2026-100820: Privilege escalation in the Address Bar component

Reporter
    Tran Quac
Impact
    moderate

References

    Bug 2071645

#CVE-2026-100821: Site isolation issue in the Panning and Zooming component

Reporter
    Nguyen Thanh Nguyen
Impact
    moderate

References

    Bug 2071784


To generate a diff of this commit:
cvs rdiff -u -r1.27 -r1.28 pkgsrc/www/firefox140/Makefile
cvs rdiff -u -r1.22 -r1.23 pkgsrc/www/firefox140/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/www/firefox140/Makefile
diff -u pkgsrc/www/firefox140/Makefile:1.27 pkgsrc/www/firefox140/Makefile:1.28
--- pkgsrc/www/firefox140/Makefile:1.27 Tue Sep 29 06:08:04 2026
+++ pkgsrc/www/firefox140/Makefile      Tue Sep 29 13:19:11 2026
@@ -1,12 +1,11 @@
-# $NetBSD: Makefile,v 1.27 2026/09/29 06:08:04 wiz Exp $
+# $NetBSD: Makefile,v 1.28 2026/09/29 13:19:11 gutteridge Exp $
 
 FIREFOX_VER=           ${MOZ_BRANCH}${MOZ_BRANCH_MINOR}
-MOZ_BRANCH=            140.16
+MOZ_BRANCH=            140.17
 MOZ_BRANCH_MINOR=      .0esr
 
 DISTNAME=      firefox-${FIREFOX_VER}.source
 PKGNAME=       ${DISTNAME:S/.source//:S/b/beta/:S/esr//:S/firefox-/firefox140-/}
-PKGREVISION=   2
 CATEGORIES=    www
 MASTER_SITES+= ${MASTER_SITE_MOZILLA:=firefox/releases/${FIREFOX_VER}/source/}
 MASTER_SITES+= ${MASTER_SITE_MOZILLA_ALL:=firefox/releases/${FIREFOX_VER}/source/}

Index: pkgsrc/www/firefox140/distinfo
diff -u pkgsrc/www/firefox140/distinfo:1.22 pkgsrc/www/firefox140/distinfo:1.23
--- pkgsrc/www/firefox140/distinfo:1.22 Tue Sep 15 13:16:58 2026
+++ pkgsrc/www/firefox140/distinfo      Tue Sep 29 13:19:11 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.22 2026/09/15 13:16:58 gutteridge Exp $
+$NetBSD: distinfo,v 1.23 2026/09/29 13:19:11 gutteridge Exp $
 
-BLAKE2s (firefox-140.16.0esr.source.tar.xz) = 787602619860678dbde4ff0ebe59db1f2a0920835b9fe6a523ac8ff7947b04d2
-SHA512 (firefox-140.16.0esr.source.tar.xz) = fabf5b481594a9a860b6ae379d2ee89ba291b807c94334ee15bad1fe862edb47c22e890d892e33d6a6ec57fce4ab12aa9c9c6fa4a501b881ecc6211ac04bd9a0
-Size (firefox-140.16.0esr.source.tar.xz) = 632581380 bytes
+BLAKE2s (firefox-140.17.0esr.source.tar.xz) = 8450cae92597fc4860dbfa42e145c587dd5022c8e2d427d1da8f480d3ff50031
+SHA512 (firefox-140.17.0esr.source.tar.xz) = c569f4f1ecbadec4c24ab60af6c8ff03f6c1292e7b2446edca7cc6f5575bd8d98e3ee9efb9877eba98bdb15354a4c4260515f8c6fd9aa9d198b26722f60ae5f4
+Size (firefox-140.17.0esr.source.tar.xz) = 637640276 bytes
 BLAKE2s (nodejs-output-140.0.4.tgz) = 7ebb5993c8c9d7d5492afdb9fa7fef74fec7753fb0b14673817f24faf4a7fca4
 SHA512 (nodejs-output-140.0.4.tgz) = e421b0b6be8b5b8dfda705eefcf4573a1270df9012dca5eac9ba0ac2af2bcc47dd66b1057106f8c2336a10bdcc39b9f852041dd33da9e7a8929d981dbb4e1fb4
 Size (nodejs-output-140.0.4.tgz) = 245385 bytes



Home | Main Index | Thread Index | Old Index