Back Linuxsecurity openSUSE 15.6 MozillaFirefox Important Security Update 2026-0871
This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.8.0 ESR (MFSA 2026-15) (bsc#1258568): * CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component * CVE-2026-2758: Use-after-free in the JavaScript: GC component * CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component * CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component * CVE-2026-2761: Sandbox escape in the Graphics: WebRender component * CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component * CVE-2026-2763: Use-after-free in the JavaScript Engine component * CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component * CVE-2026-2765: Use-after-free in the JavaScript Engine component * CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component * CVE-2026-2767:
## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-871=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-871=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-871=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-871=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-871=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-871=1 * openSUSE Leap 15.6 zypper in -t patch Read the Full Advisory
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-871=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-871=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-871=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-871=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-871=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-871=1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debugsource-140.8.0-150200.152.222.1 * MozillaFirefox-translations-other-140.8.0-150200.152.222.1 * MozillaFirefox-debuginfo-140.8.0-150200.152.222.1 * MozillaFirefox-translations-common-140.8.0-150200.152.222.1 * MozillaFirefox-140.8.0-150200.152.222.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-140.8.0-150200.152.222.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debugsource-140.8.0-150200.152.222.1 * MozillaFirefox-translations-other-140.8.0-150200.152.222.1 * MozillaFirefox-debuginfo-140.8.0-150200.152.222.1 * MozillaFirefox-translations-common-140.8.0-150200.152.222.1 * MozillaFirefox-140.8.0-150200.152.222.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-140.8.0-150200.152.222.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 Read the Full Advisory
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* MozillaFirefox-debugsource-140.8.0-150200.152.222.1
* MozillaFirefox-translations-other-140.8.0-150200.152.222.1
* MozillaFirefox-debuginfo-140.8.0-150200.152.222.1
* MozillaFirefox-translations-common-140.8.0-150200.152.222.1
* MozillaFirefox-140.8.0-150200.152.222.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* MozillaFirefox-devel-140.8.0-150200.152.222.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* MozillaFirefox-debugsource-140.8.0-150200.152.222.1
* MozillaFirefox-translations-other-140.8.0-150200.152.222.1
* MozillaFirefox-debuginfo-140.8.0-150200.152.222.1
* MozillaFirefox-translations-common-140.8.0-150200.152.222.1
* MozillaFirefox-140.8.0-150200.152.222.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* MozillaFirefox-devel-140.8.0-150200.152.222.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64
* bsc#1258568 ## References: * * * * * * * * * * * * * * * * * * Read the Full Advisory
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
