[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6254-1] firefox-esr security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6254-1] firefox-esr security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Fri, 8 May 2026 18:17:53 +0000 Message-id: <[🔎] af4o0QjnCGMJaQ24@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6254-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 08, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2026-8090 CVE-2026-8092 CVE-2026-8094 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 140.10.2esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 140.10.2esr-1~deb13u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmn+KKMACgkQEMKTtsN8 TjY6Hg//VUiTgHRG6MfKKzk10FFtDC4XtaUtclVL4Dw8fOUg/rSXqwuAiJgdG1R9 fsh0OHt9boy/MRzgDV3qzJpYe+VjdI8TS9qb0pl/GvWYodunna/5sgVPlMSRVaE6 00KgZ18HShZsmj2qACaFJ/B4eSx2yrf9Gs992DyXV3eYNCUnHHNTUBuANm5pLCGN 0ITRzV56grqtBIJ5WBwU54xioB2VPDOFjrScjDQPH/CuzAiMPA8vo2RdPTV89jnG t9qnOv/z4RYrCAHcQeSBmQmKo7E5zXpJ2KdOcJxORnhftn38Db1CMJ7L86gMUEiR t1CR3UI+k8Mcvse3/Q84Wt5dtAXgjwhgGrcWPATLLkKgGRNMolJFhEjgZ/FmNBBL CT7R2ADfEQCfFUuV/el5M9v81LKwdINP/NFQq0wOelMeivc9wb+8jCGrwqzmUqxL 9q9fNp7XsLWdMxErkUQDROPNvAbGnsLPJBhPLHCPhOUv9I3dH/UhWYvb+f5GPoxL d4vVpRzZzPGny4cYWiCP1Qh322yAG8UTXGPoCJQBbeJV7UPYzTJ3WbyfoUf5ePlM X6diI8YAFr0NiRyqMtXZjwd2Vve4YHBptuTSfchYCw7TC6Pf8seoQjXKesViPiEP 5cJOEDczLzSdwL64D0I7CPtGIsfN4yeKSGTgkdO3+X9ySieHLf0= =XRwj -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6253-1] linux security update Next by Date: [SECURITY] [DSA 6255-1] php8.2 security update Previous by thread: [SECURITY] [DSA 6253-1] linux security update Next by thread: [SECURITY] [DSA 6255-1] php8.2 security update Index(es): Date Thread
This Debian Security Advisory addresses multiple high-severity vulnerabilities (CVE-2026-8090, CVSS 7.3; CVE-2026-8092, CVSS 8.1; CVE-2026-8094) in Firefox ESR that could lead to arbitrary code execution. For Debian Bookworm, the issues are fixed in firefox-esr version 140.10.2esr-1~deb12u1, and for Trixie, in version 140.10.2esr-1~deb13u1. IT administrators should prioritize upgrading affected packages to these patched versions.