pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/www/firefox140



Module Name:    pkgsrc
Committed By:   gutteridge
Date:           Tue Jul 21 16:30:32 UTC 2026

Modified Files:
        pkgsrc/www/firefox140: Makefile distinfo

Log Message:
firefox140: update to 140.13

Mozilla Foundation Security Advisory 2026-70
Security Vulnerabilities fixed in Firefox ESR 140.13

Announced
    July 21, 2026
Impact
    critical
Products
    Firefox ESR
Fixed in

        Firefox ESR 140.13

#CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component

Reporter
    Christian Holler
Impact
    critical

Description

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.
References

    Bug 2045443

#CVE-2026-15719: Site isolation issue in the DOM: Navigation component

Reporter
    Atsushi Sada
Impact
    critical

Description

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.
References

    Bug 2043820

#CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component

Reporter
    Tran Quac
Impact
    high

References

    Bug 2034682

#CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component

Reporter
    Tomoya Nakanishi
Impact
    high

References

    Bug 2042033

#CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component

Reporter
    crixer
Impact
    high

References

    Bug 2043188

#CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component

Reporter
    Yaqoub Aldurayhim
Impact
    high

References

    Bug 2045468

#CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component

Reporter
    Oskar L
Impact
    high

References

    Bug 2046416

#CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component

Reporter
    Nebula Security
Impact
    high

References

    Bug 2047689

#CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component

Reporter
    fedek
Impact
    high

References

    Bug 2049523

#CVE-2026-16354: Information disclosure in the Graphics: ImageLib component

Reporter
    satyamasd
Impact
    high

References

    Bug 2050626

#CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component

Reporter
    Nebula Security
Impact
    high

References

    Bug 2051015

#CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component

Reporter
    Amy Burnett of OpenAI
Impact
    high

References

    Bug 2051854

#CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component

Reporter
    Amy Burnett of OpenAI
Impact
    high

References

    Bug 2052207

#CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component

Reporter
    Oskar L
Impact
    high

References

    Bug 2052562

#CVE-2026-16357: Incorrect boundary conditions in the Graphics component

Reporter
    5up3rh3i
Impact
    high

References

    Bug 2053326

#CVE-2026-16371: Privilege escalation in the DOM: Navigation component

Reporter
    stevej
Impact
    moderate

References

    Bug 2008369

#CVE-2026-16374: Information disclosure in the Framework component in DevTools

Reporter
    Tomoya Nakanishi
Impact
    moderate

References

    Bug 2027519

#CVE-2026-16375: Site isolation issue in the Networking: HTTP component

Reporter
    pakhunov.anton.n
Impact
    moderate

References

    Bug 2032140

#CVE-2026-16377: Mitigation bypass in the PDF Viewer component

Reporter
    Nikola Kojic
Impact
    moderate

References

    Bug 2037770

#CVE-2026-16379: Privilege escalation in the DOM: Content Processes component

Reporter
    Shu Takahashi
Impact
    moderate

References

    Bug 2039452

#CVE-2026-16358: Site isolation issue in the Graphics: WebRender component

Reporter
    Hcamael
Impact
    moderate

References

    Bug 2040119

#CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component

Reporter
    Rintaro Kawasugi
Impact
    moderate

References

    Bug 2041001

#CVE-2026-16383: Mitigation bypass in the DOM: Networking component

Reporter
    Ibuki Sato and Tomoya Nakanishi
Impact
    moderate

References

    Bug 2041902

#CVE-2026-16387: Site isolation issue in the Networking component

Reporter
    Atsushi Sada
Impact
    moderate

References

    Bug 2043200

#CVE-2026-16390: Mitigation bypass in the Enterprise Policies component

Reporter
    Souma Ohsawa
Impact
    moderate

References

    Bug 2044527

#CVE-2026-16391: Information disclosure in the Storage: IndexedDB component

Reporter
    Tomoya Nakanishi
Impact
    moderate

References

    Bug 2044536

#CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component

Reporter
    Jacolon Walker
Impact
    moderate

References

    Bug 2045424

#CVE-2026-16396: Privilege escalation in WebExtensions

Reporter
    Quy Pham
Impact
    moderate

References

    Bug 2047240

#CVE-2026-16405: Information disclosure in the Networking: WebSockets component

Reporter
    Yaqoub Aldurayhim
Impact
    low

References

    Bug 2036591

#CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153

Reporter
    Christian Holler, Frederik Braun, Justin Link, Simon Friedberger, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
Impact
    high

Description

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been 
exploited to run arbitrary code.
References

    High-severity memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
    Moderate-severity memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
    Low-severity memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153

#CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153

Reporter
    Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla and the Mozilla Fuzzing Team
Impact
    high

Description

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these 
could have been exploited to run arbitrary code.
References

    High-severity memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
    Moderate-severity memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153

#CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13

Reporter
    The Mozilla Fuzzing Team
Impact
    high

Description

Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been 
exploited to run arbitrary code.
References

    High-severity memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13


To generate a diff of this commit:
cvs rdiff -u -r1.20 -r1.21 pkgsrc/www/firefox140/Makefile
cvs rdiff -u -r1.18 -r1.19 pkgsrc/www/firefox140/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/www/firefox140/Makefile
diff -u pkgsrc/www/firefox140/Makefile:1.20 pkgsrc/www/firefox140/Makefile:1.21
--- pkgsrc/www/firefox140/Makefile:1.20 Mon Jul 13 04:36:34 2026
+++ pkgsrc/www/firefox140/Makefile      Tue Jul 21 16:30:32 2026
@@ -1,12 +1,11 @@
-# $NetBSD: Makefile,v 1.20 2026/07/13 04:36:34 wiz Exp $
+# $NetBSD: Makefile,v 1.21 2026/07/21 16:30:32 gutteridge Exp $
 
 FIREFOX_VER=           ${MOZ_BRANCH}${MOZ_BRANCH_MINOR}
-MOZ_BRANCH=            140.12
+MOZ_BRANCH=            140.13
 MOZ_BRANCH_MINOR=      .0esr
 
 DISTNAME=      firefox-${FIREFOX_VER}.source
 PKGNAME=       ${DISTNAME:S/.source//:S/b/beta/:S/esr//:S/firefox-/firefox140-/}
-PKGREVISION=   1
 CATEGORIES=    www
 MASTER_SITES+= ${MASTER_SITE_MOZILLA:=firefox/releases/${FIREFOX_VER}/source/}
 MASTER_SITES+= ${MASTER_SITE_MOZILLA_ALL:=firefox/releases/${FIREFOX_VER}/source/}

Index: pkgsrc/www/firefox140/distinfo
diff -u pkgsrc/www/firefox140/distinfo:1.18 pkgsrc/www/firefox140/distinfo:1.19
--- pkgsrc/www/firefox140/distinfo:1.18 Tue Jun 16 16:16:43 2026
+++ pkgsrc/www/firefox140/distinfo      Tue Jul 21 16:30:32 2026
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.18 2026/06/16 16:16:43 gutteridge Exp $
+$NetBSD: distinfo,v 1.19 2026/07/21 16:30:32 gutteridge Exp $
 
-BLAKE2s (firefox-140.12.0esr.source.tar.xz) = 5aa6d7e2025eda47afca489720e6511c9aa29875699d021fc03068eaeb2b1486
-SHA512 (firefox-140.12.0esr.source.tar.xz) = 3d598dd964bca074d11b71f84d586811b0a736bdd4d1e6cedb9286c56b1e11584e85ca1d0369c9b2f8d9e4d0eaf014d1b9232a96e71ac25f71fa9ed0807f642d
-Size (firefox-140.12.0esr.source.tar.xz) = 641934156 bytes
+BLAKE2s (firefox-140.13.0esr.source.tar.xz) = ea85681fc369dc74f8637b1182840a2c3be8dc94bfbb5666e7bf53f46625cf9e
+SHA512 (firefox-140.13.0esr.source.tar.xz) = 937a4103d71c5e1e4bf051821729f6ea70b5c18d444930a487695cc23d74712a0134047248f6ac02305e01becb705426a55b9d89739f02a01eda01ecf5bc27f1
+Size (firefox-140.13.0esr.source.tar.xz) = 644768324 bytes
 BLAKE2s (nodejs-output-140.0.4.tgz) = 7ebb5993c8c9d7d5492afdb9fa7fef74fec7753fb0b14673817f24faf4a7fca4
 SHA512 (nodejs-output-140.0.4.tgz) = e421b0b6be8b5b8dfda705eefcf4573a1270df9012dca5eac9ba0ac2af2bcc47dd66b1057106f8c2336a10bdcc39b9f852041dd33da9e7a8929d981dbb4e1fb4
 Size (nodejs-output-140.0.4.tgz) = 245385 bytes



Home | Main Index | Thread Index | Old Index