Skip to content
openSUSE: MozillaFirefox Important Privilege Escalation Issues 2026:20014

openSUSE: MozillaFirefox Important Privilege Escalation Issues 2026:20014

Linuxsecurity •LinuxSecurity Advisories • January 13, 2026

This update for MozillaFirefox fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 140.6.0 ESR was released: * Fixed: Various security fixes. MFSA 2025-94 (bsc#1254551): * CVE-2025-14321: Use-after-free in the WebRTC: Signaling component * CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2025-14323: Privilege escalation in the DOM: Notifications component * CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2025-14328: Privilege escalation in the Netmonitor component * CVE-2025-14329: Privilege escalation in the Netmonitor component * CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2025-14331: Same-origin policy bypass in the Request Handling component * CVE-2025-14333: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird

- openSUSE Leap 16.0: MozillaFirefox-140.6.0-160000.1.1 MozillaFirefox-branding-upstream-140.6.0-160000.1.1 MozillaFirefox-devel-140.6.0-160000.1.1 MozillaFirefox-translations-common-140.6.0-160000.1.1 MozillaFirefox-translations-other-140.6.0-160000.1.1

- openSUSE Leap 16.0:

MozillaFirefox-140.6.0-160000.1.1

MozillaFirefox-branding-upstream-140.6.0-160000.1.1

MozillaFirefox-devel-140.6.0-160000.1.1

MozillaFirefox-translations-common-140.6.0-160000.1.1

MozillaFirefox-translations-other-140.6.0-160000.1.1

* bsc#1254551 References: * * * * * * * * * *

*

*

*

*

*

*

*

*

*

*