Debian Releases Security Updates for firefox-esr Due to Critical Vulnerabilities

Debian Releases Security Updates for firefox-esr Due to Critical Vulnerabilities

First seen 16 Jan 2026, 05:57 UTC Linuxsecurity 18.3

Article Content

Browse articles
ThreatCluster

Debian has released security updates for the firefox-esr package to address critical vulnerabilities, including a sandbox escape and privilege escalation. Users of the oldstable distribution (bookworm) and stable distribution (trixie) are advised to upgrade to the patched versions 140.7.0esr-1~deb12u1 and 140.7.0esr-1~deb13u1, respectively. The vulnerabilities could potentially allow for code execution and privilege escalation.