[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6283-1] firefox-esr security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6283-1] firefox-esr security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Wed, 20 May 2026 18:59:26 +0000 Message-id: <[🔎] ag4EjpQ6h5zIkGgM@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6283-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 20, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2026-8388 CVE-2026-8391 CVE-2026-8401 CVE-2026-8946 CVE-2026-8947 CVE-2026-8950 CVE-2026-8953 CVE-2026-8954 CVE-2026-8955 CVE-2026-8956 CVE-2026-8957 CVE-2026-8958 CVE-2026-8961 CVE-2026-8962 CVE-2026-8968 CVE-2026-8970 CVE-2026-8974 CVE-2026-8975 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, bypass of the same-origin policy, privilege escalation, information disclosure, spoofing or sandbox escape. For the oldstable distribution (bookworm), these problems have been fixed in version 140.11.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 140.11.0esr-1~deb13u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmoN+nkACgkQEMKTtsN8 TjZUxQ/+Kjw43a22PIICefFAqne7P9rU6PVkI28HPI0hLgxitlg+77Ti8Y8/1vza z8SRnkQD0oxYnQXVoTS8HlLWcp9Q3/s70yXNIDnSWd9HGlavPHj2s2cH/Qtn/GL/ /c2WmjScpm537nAG9H3CV3B5LDRhVwZMGcntuVYUDKSpZJ91nW9cYYTLaaflp6H+ CQE2YL+I+dqf980TZao2dk96d3n00KPqDSgI1AJnhUY4vybyBrMGU/9ubZnWd3VU s5do3quUljzItqFZkks0BAkoBtVHuKVHlVDAraU1j22woJRDOh6J2clCbyXfthOa MznJmyBLtoJre7Funlo3GHWlE50G2bGyUSJzxN+qV9Shq4ZjxlJ4sXbqvPqOqRpZ fTa6FdQ/E/4MVwZh0jQReFYazHPjoaUIHmXKAdBpE9Ogvp/zXcJ85a/CBXWHcsk7 5QzXadU52afdDQv1XX/yJlzTa4kFfuRwcR37JS2b0DRdFYR0E99JVQCmacDGMBXB +8pmrC693REwBTdp1qSX2ydj1gc6ZcXV+Wed3AWZb+Qv/pMB4AwesgsJY61YoTBh XcCd4g3tlSoLdjGot2yNJ9r6yN+f6Tfmdt6lUPQu2V9/VkMUu9w0h9v0X8VR5l1g rSumYNFCJ4k74ad1z/pREhkZd6IzlCjLRVlDRbHJLVXIceEi15o= =gB8L -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6282-1] rsync security update Next by Date: [SECURITY] [DSA 6284-1] pdns security update Previous by thread: [SECURITY] [DSA 6282-1] rsync security update Next by thread: [SECURITY] [DSA 6284-1] pdns security update Index(es): Date Thread
This Debian security advisory addresses multiple vulnerabilities in Firefox ESR, including CVE-2026-8401, a critical flaw (CVSS 9.8) allowing arbitrary code execution. According to NVD data, Firefox versions prior to 150.0.3 are affected. The fix requires upgrading to Firefox ESR version 140.11.0esr-1~deb12u1 for Debian Bookworm or 140.11.0esr-1~deb13u1 for Debian Trixie.