head 1.23; access; symbols pkgsrc-2026Q3:1.22.0.2 pkgsrc-2026Q3-base:1.22 pkgsrc-2026Q2:1.18.0.2 pkgsrc-2026Q2-base:1.18 pkgsrc-2026Q1:1.11.0.2 pkgsrc-2026Q1-base:1.11 pkgsrc-2025Q4:1.4.0.2 pkgsrc-2025Q4-base:1.4; locks; strict; comment @# @; 1.23 date 2026.09.29.13.19.11; author gutteridge; state Exp; branches; next 1.22; commitid FnAL8lPskSa8fwXG; 1.22 date 2026.09.15.13.16.58; author gutteridge; state Exp; branches; next 1.21; commitid SwAoD2iUPVLmGIVG; 1.21 date 2026.09.01.16.02.34; author gutteridge; state Exp; branches; next 1.20; commitid NbuE2E0lPDsC2WTG; 1.20 date 2026.08.19.02.36.12; author gutteridge; state Exp; branches; next 1.19; commitid Ps3QhIKiwfx50cSG; 1.19 date 2026.07.21.16.30.32; author gutteridge; state Exp; branches; next 1.18; commitid ZxntcfgzCDzgyxOG; 1.18 date 2026.06.16.16.16.43; author gutteridge; state Exp; branches 1.18.2.1; next 1.17; commitid isTpUgWSiKChB2KG; 1.17 date 2026.05.21.15.34.06; author gutteridge; state Exp; branches; next 1.16; commitid 7T50CRi41dfkcHGG; 1.16 date 2026.05.07.20.25.32; author gutteridge; state Exp; branches; next 1.15; commitid iWQ3iojshMyrgVEG; 1.15 date 2026.04.30.21.47.25; author gutteridge; state Exp; branches; next 1.14; commitid AL03i2xn9GmUV1EG; 1.14 date 2026.04.30.18.51.22; author gutteridge; state Exp; branches; next 1.13; commitid yKrZQOCM2JcYX0EG; 1.13 date 2026.04.21.13.40.08; author gutteridge; state Exp; branches; next 1.12; commitid D87keWPDmUVexPCG; 1.12 date 2026.04.09.18.37.06; author gutteridge; state Exp; branches; next 1.11; commitid 3tYWuzeMsO94zjBG; 1.11 date 2026.03.24.13.11.35; author gutteridge; state Exp; branches 1.11.2.1; next 1.10; commitid OQxDJoo44o6ghezG; 1.10 date 2026.02.24.14.07.55; author gutteridge; state Exp; branches; next 1.9; commitid e6LxN1xHBOyguDvG; 1.9 date 2026.02.17.00.26.49; author gutteridge; state Exp; branches; next 1.8; commitid r8ldzyvFdlHkaFuG; 1.8 date 2026.01.13.17.20.06; author gutteridge; state Exp; branches; next 1.7; commitid hqngZbAqcqMiTfqG; 1.7 date 2026.01.06.23.27.50; author gutteridge; state Exp; branches; next 1.6; commitid j97VjMVViBWP9opG; 1.6 date 2026.01.02.14.27.02; author tnn; state Exp; branches; next 1.5; commitid IofESGCby2yEiPoG; 1.5 date 2025.12.24.02.11.49; author gutteridge; state Exp; branches; next 1.4; commitid fKiRo3GRfeZ9wBnG; 1.4 date 2025.12.15.21.04.49; author gutteridge; state Exp; branches 1.4.2.1; next 1.3; commitid ifEhwQDHE5dK4ymG; 1.3 date 2025.12.11.11.05.21; author leot; state Exp; branches; next 1.2; commitid Jl8MdNyMAsEOSYlG; 1.2 date 2025.11.12.19.48.10; author leot; state Exp; branches; next 1.1; commitid c5kiPkEu7aPWHiiG; 1.1 date 2025.10.19.11.56.55; author leot; state Exp; branches; next ; commitid O4nVQ7B6izcESafG; 1.18.2.1 date 2026.07.22.15.14.11; author maya; state Exp; branches; next 1.18.2.2; commitid vRSFMuMrtjgh6FOG; 1.18.2.2 date 2026.08.24.19.38.48; author maya; state Exp; branches; next ; commitid 2C4kdQsgJFgivVSG; 1.11.2.1 date 2026.04.10.19.09.35; author bsiegert; state Exp; branches; next 1.11.2.2; commitid FTTeGhuFkwkjIrBG; 1.11.2.2 date 2026.04.22.14.32.19; author maya; state Exp; branches; next 1.11.2.3; commitid iDHLLUhOplH6NXCG; 1.11.2.3 date 2026.04.26.19.35.21; author bsiegert; state Exp; branches; next 1.11.2.4; commitid M5E5QUqdg03glvDG; 1.11.2.4 date 2026.05.02.19.26.59; author bsiegert; state Exp; branches; next 1.11.2.5; commitid idHf729mVYiq6hEG; 1.11.2.5 date 2026.05.08.11.16.50; author maya; state Exp; branches; next 1.11.2.6; commitid HGEyfAIx2h2kc0FG; 1.11.2.6 date 2026.05.24.09.00.09; author bsiegert; state Exp; branches; next ; commitid EtMrmv36WTnxV2HG; 1.4.2.1 date 2025.12.26.10.41.36; author bsiegert; state Exp; branches; next 1.4.2.2; commitid KkEVuCr8qkaihUnG; 1.4.2.2 date 2026.01.14.18.58.46; author maya; state Exp; branches; next 1.4.2.3; commitid xVspYetx9XpZpoqG; 1.4.2.3 date 2026.02.28.20.14.29; author bsiegert; state Exp; branches; next ; commitid nTJO074MkAchobwG; desc @@ 1.23 log @firefox140: update to 140.17 Mozilla Foundation Security Advisory 2026-99 Security Vulnerabilities fixed in Firefox ESR 140.17 Announced September 29, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.17 Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug. #CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component Reporter Mozilla Impact high References Bug 2047721 #CVE-2026-100757: Use-after-free in the Widget component Reporter Mohamed Mbarek Impact high References Bug 2049352 #CVE-2026-100758: Sandbox escape in the DOM: Navigation component Reporter Mozilla Impact high References Bug 2049792 #CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager component Reporter Mozilla Impact high References Bug 2054736 #CVE-2026-100762: Sandbox escape due to use-after-free in the DOM: Content Processes component Reporter Yaqoub Aldurayhim Impact high References Bug 2059404 #CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component Reporter Mozilla Impact high References Bug 2061245 #CVE-2026-100766: Information disclosure in the Networking: JAR component Reporter Mozilla Impact high References Bug 2061526 #CVE-2026-100767: Use-after-free in the Networking: Cache component Reporter Mozilla Impact high References Bug 2063680 #CVE-2026-100769: Use-after-free in the JavaScript: WebAssembly component Reporter Tomer Fichman Impact high References Bug 2067190 #CVE-2026-100770: Sandbox escape due to use-after-free in the DOM: Content Processes component Reporter Mozilla Impact high References Bug 2068322 #CVE-2026-100771: Undefined behavior in the DOM: Streams component Reporter Mozilla Impact high References Bug 2068336 #CVE-2026-100772: Use-after-free in the DOM: Core & HTML component Reporter Mozilla Impact high References Bug 2068340 #CVE-2026-100773: Use-after-free in the Storage: IndexedDB component Reporter Mozilla Impact high References Bug 2068346 #CVE-2026-100774: Use-after-free in the DOM: Core & HTML component Reporter Mozilla Impact high References Bug 2068351 #CVE-2026-100775: Sandbox escape in the Graphics component Reporter Mozilla Impact high References Bug 2068367 #CVE-2026-100776: Use-after-free in the JavaScript: WebAssembly component Reporter Mozilla Impact high References Bug 2068374 #CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component Reporter Mozilla Impact high References Bug 2068375 #CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core & HTML component Reporter Mozilla Impact high References Bug 2068406 #CVE-2026-100779: Use-after-free in the XSLT component Reporter Mozilla Impact high References Bug 2068417 #CVE-2026-100780: Use-after-free in the DOM: Core & HTML component Reporter Mozilla Impact high References Bug 2068422 #CVE-2026-100781: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component Reporter Mozilla Impact high References Bug 2068434 #CVE-2026-100782: Privilege escalation due to incorrect boundary conditions in the Graphics component Reporter Mozilla Impact high References Bug 2068456 #CVE-2026-100783: Uninitialized memory in the Audio/Video component Reporter 5up3rh3i Impact high References Bug 2069804 #CVE-2026-100784: Use-after-free in the Layout: Text and Fonts component Reporter 5up3rh3i Impact high References Bug 2070264 #CVE-2026-100785: Use-after-free in the DOM: Core & HTML component Reporter Mozilla Impact high References Bug 2071064 #CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics component Reporter Mozilla Impact high References Bug 2071067 #CVE-2026-100788: Invalid pointer in the JavaScript: WebAssembly component Reporter Mozilla Impact high References Bug 2072413 #CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component Reporter Mozilla Impact high References Bug 2072429 #CVE-2026-100790: Use-after-free in the XSLT component Reporter Mozilla Impact high References Bug 2072432 #CVE-2026-100791: Use-after-free in the DOM: Core & HTML component Reporter Mozilla Impact high References Bug 2072433 #CVE-2026-100832: Use-after-free in the Graphics: Canvas2D component Reporter Mozilla Impact high References Bug 2072467 #CVE-2026-100792: JIT miscompilation in the JavaScript: WebAssembly component Reporter Amy Burnett of OpenAI Impact high References Bug 2073266 #CVE-2026-100794: Sandbox escape due to incorrect boundary conditions in the Internationalization component Reporter Mozilla Impact moderate References Bug 2028871 #CVE-2026-96869: Information disclosure in the Networking component Reporter Carlo Di Dato Impact moderate References Bug 2041248 #CVE-2026-100797: Privilege escalation due to use-after-free in the Graphics: WebRender component Reporter Mozilla Impact moderate References Bug 2050542 #CVE-2026-100801: Privilege escalation in the DLL Services component Reporter Mozilla Impact moderate References Bug 2057112 #CVE-2026-100803: Same-origin policy bypass in the WebExtensions component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2057988 #CVE-2026-100807: Privilege escalation in the DOM: Service Workers component Reporter Khanh Nguyen Impact moderate References Bug 2062740 #CVE-2026-100811: Sandbox escape due to use-after-free in the DOM: Core & HTML component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2067973 #CVE-2026-100818: Sandbox escape due to use-after-free in the Widget: Gtk component Reporter Mozilla Impact moderate References Bug 2069399 #CVE-2026-100819: Sandbox escape due to incorrect boundary conditions in the XPCOM component Reporter Mozilla Impact moderate References Bug 2071069 #CVE-2026-100820: Privilege escalation in the Address Bar component Reporter Tran Quac Impact moderate References Bug 2071645 #CVE-2026-100821: Site isolation issue in the Panning and Zooming component Reporter Nguyen Thanh Nguyen Impact moderate References Bug 2071784 @ text @$NetBSD: distinfo,v 1.22 2026/09/15 13:16:58 gutteridge Exp $ BLAKE2s (firefox-140.17.0esr.source.tar.xz) = 8450cae92597fc4860dbfa42e145c587dd5022c8e2d427d1da8f480d3ff50031 SHA512 (firefox-140.17.0esr.source.tar.xz) = c569f4f1ecbadec4c24ab60af6c8ff03f6c1292e7b2446edca7cc6f5575bd8d98e3ee9efb9877eba98bdb15354a4c4260515f8c6fd9aa9d198b26722f60ae5f4 Size (firefox-140.17.0esr.source.tar.xz) = 637640276 bytes BLAKE2s (nodejs-output-140.0.4.tgz) = 7ebb5993c8c9d7d5492afdb9fa7fef74fec7753fb0b14673817f24faf4a7fca4 SHA512 (nodejs-output-140.0.4.tgz) = e421b0b6be8b5b8dfda705eefcf4573a1270df9012dca5eac9ba0ac2af2bcc47dd66b1057106f8c2336a10bdcc39b9f852041dd33da9e7a8929d981dbb4e1fb4 Size (nodejs-output-140.0.4.tgz) = 245385 bytes SHA1 (patch-browser_app_profile_firefox.js) = bc719edef37d18655ba79b030270438ee166fdaf SHA1 (patch-build_moz.configure_init.configure) = 65deb3c233df0aab81eb1fca05d708e5a4ed169a SHA1 (patch-build_moz.configure_rust.configure) = 25ddfacd29cebbc6db005dbe61a2a7446d480678 SHA1 (patch-config_gcc-stl-wrapper.template.h) = 9d1f15ff487efa9202114d19ed5668b4e7aa032a SHA1 (patch-config_makefiles_rust.mk) = 3366ab089a23e66230e7e23749c10db38018fdd4 SHA1 (patch-dom_base_nsAttrName.h) = ac7ba441a3b27df2855cf2673eea36b1cb44ad49 SHA1 (patch-dom_webtransport_api_WebTransportDatagramDuplexStream.cpp) = b93b4c6367bd2fb3d1868ab7d97ca56c100be414 SHA1 (patch-gfx_angle_checkout_src_common_third__party_smhasher_src_PMurHash.cpp) = e458c9c8dc66edc69c1874734af28a77fc5e3993 SHA1 (patch-gfx_angle_checkout_src_compiler_translator_InfoSink.h) = b2adce9e65662283a11b6dcff40e95523e940045 SHA1 (patch-gfx_ots_src_name.cc) = 35ae5b2689eae8fab1ea351612f3628c14001f9e SHA1 (patch-gfx_skia_skia_src_sksl_codegen_SkSLSPIRVCodeGenerator.cpp) = 3eb9855e20fe8b7784a9620fce4ffb96f4736f82 SHA1 (patch-intl_lwbrk_LineBreaker.cpp) = 46914fd55257c13021d697cbd309ae4db3b9c029 SHA1 (patch-ipc_chromium_src_base_message__pump__libevent.cc) = 298642a3527804115b398fb7904a3596962932e3 SHA1 (patch-ipc_chromium_src_base_platform__thread__posix.cc) = 753bb4e90758f5b42a51bbc073b328de673988cf SHA1 (patch-ipc_glue_GeckoChildProcessHost.cpp) = 63fbee04321f7ade20db4ccc1a1218b848344ce1 SHA1 (patch-js-src-jit-arm64-vixl-MozCpu-vixl.cpp) = d90fca47d79551fd74214d47f8184670b901b792 SHA1 (patch-js_public_Utility.h) = bb5464a0398b91693ab362e6b9b06d48429b9e7d SHA1 (patch-js_src_jit_FlushICache.cpp) = f5d1fcb391c36a29fb71a78dbf731ee6a1cb17b6 SHA1 (patch-js_src_util_NativeStack.cpp) = a0a16d8d8d78d3cc3f4d2a508586f1a7821f7dba SHA1 (patch-js_src_vm_TypedArrayObject-inl.h) = e7913c8d4b2b05b67040baa64dae62d6ba40390e SHA1 (patch-media_ffvpx_libavutil_arm_bswap.h) = ae89120862442275d6b14446c5a63b0ef570124f SHA1 (patch-media_libpng_pngpriv.h) = 8320a1f7534ed5c4914b597bb3d6117d0060318f SHA1 (patch-modules_fdlibm_src_math__private.h) = e20b6c23011d7123cbbd64a500eb8ce8c426620e SHA1 (patch-netwerk_protocol_http_nsHttpHandler.cpp) = 67493b4635041d21ff9fbfda80b3197fed542a26 SHA1 (patch-nsprpub_pr_src_pthreads_ptsynch.c) = 753fd4d62088c870aefe7c4b739286259848446e SHA1 (patch-python_mozbuild_mozbuild_backend_recursivemake.py) = 5be4183d9075f5a3a3c6b3e0338473af185fb50e SHA1 (patch-python_mozbuild_mozbuild_frontend_reader.py) = 57cad432ccc18e790e2cf00732f499116c79f4c1 SHA1 (patch-third__party_abseil-cpp_absl_debugging_internal_elf__mem__image.cc) = 3c015fe094aa1d4e8259a7cda08ce06e0ae506f0 SHA1 (patch-third__party_abseil-cpp_absl_debugging_internal_vdso__support.cc) = f9c44d0d6fd952296f23c24f56053958b30d8e5c SHA1 (patch-third__party_js_cfworker_build.sh) = 46cdf97b99cf01080f290ae8d9a33b5f869fc3e4 SHA1 (patch-third__party_libwebrtc_modules_audio__device_audio__device__impl.cc) = 47ba1a2b88b3fdfd16cd29da3eb1e4a218ecada8 SHA1 (patch-third__party_libwebrtc_modules_desktop__capture_desktop__capture__gn_moz.build) = d0454784eb72be49162f619579e060a0de3c480f SHA1 (patch-third__party_libwebrtc_modules_desktop__capture_linux_wayland_egl__dmabuf.cc) = 455be625b5de2f6f1f4b2dbb6c8cb33ca16c2583 SHA1 (patch-third__party_libwebrtc_modules_video__capture_linux_device__info__v4l2.cc) = 8831d477f14fd4f8f735ff0c1a322cba8c70e277 SHA1 (patch-third__party_libwebrtc_modules_video__capture_linux_video__capture__v4l2.cc) = 8111952a107eb2cd665525ddd0e27c79eee3c1cd SHA1 (patch-third__party_libwebrtc_modules_video__capture_video__capture__options.cc) = e15f7e365ef6d57cd262f920f49c4d73f3a13305 SHA1 (patch-third__party_libwebrtc_rtc__base_memory__usage.cc) = f8d926d400bf3df107127823eac27816f4b85644 SHA1 (patch-third__party_libwebrtc_rtc__base_physical__socket__server.cc) = 6909c4da9e7b3785252e5bce9be0ff47ebb87e01 SHA1 (patch-third__party_libwebrtc_rtc__base_platform__thread__types.cc) = 8ae75100775037347008d168eedc151e0e993b0f SHA1 (patch-third__party_libwebrtc_system__wrappers_source_cpu__features__linux.cc) = b90e22b50879f7adcc1da3a993f52c0701b720f8 SHA1 (patch-third__party_python_dlmanager_check.py) = 69054522d8ced8cb47e65e5a8b1a87ed5ce6708e SHA1 (patch-third__party_python_jsonschema_jsonschema_validators.py) = 24c84c8f8ca2bc39088001dffdcb05be3ac84c76 SHA1 (patch-third__party_sqlite3_ext_moz.build) = 026483e9cdc61eda80b699978b1677e1b6d3ff6d SHA1 (patch-third__party_sqlite3_src_moz.build) = b26856a4b87aa12211575d9982f62dc899474b52 SHA1 (patch-third__party_wasm2c_src_c-writer.cc) = 38eb2ee0e00722aa1380540b83648b43723719aa SHA1 (patch-third__party_wasm2c_src_prebuilt_wasm2c__source__includes.cc) = 99d0db944f0c2d0c623460991efd423d9127c988 SHA1 (patch-toolkit_components_terminator_nsTerminator.cpp) = e905e38ef1b88d764c695c019f15609350c1c43b SHA1 (patch-toolkit_moz.configure) = 1306e7ac3c3939886aff38a58dd3162e6517409b SHA1 (patch-toolkit_mozapps_installer_packager.mk) = 706635b76a7b525794aba95e95544f09e18bb662 SHA1 (patch-xpcom_base_nscore.h) = 1ac4d34d3c9e80bc1ac966c6c84cb320bc0fa1ec SHA1 (patch-xpcom_reflect_xptcall_md_unix_moz.build) = 8980398051fa16c7283acb6d323419993cce1420 @ 1.22 log @firefox140: update to 140.16 Mozilla Foundation Security Advisory 2026-92 Security Vulnerabilities fixed in Firefox ESR 140.16 Announced September 15, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.16 Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug. #CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component Reporter devdharan9424@@gmail.com Impact high References Bug 2056051 #CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mozilla Impact high References Bug 2057121 #CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mozilla Impact high References Bug 2058064 #CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mozilla Impact high References Bug 2058065 #CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mozilla Impact high References Bug 2058066 #CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mozilla Impact high References Bug 2058067 #CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mozilla Impact high References Bug 2058068 #CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mozilla Impact high References Bug 2058069 #CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mozilla Impact high References Bug 2058078 #CVE-2026-92014: Privilege escalation due to incorrect boundary conditions in the Graphics component Reporter Jacolon Walker Impact high References Bug 2060000 #CVE-2026-92015: Privilege escalation in the WebExtensions component Reporter Quy Pham Impact high References Bug 2060235 #CVE-2026-92016: Use-after-free in the Disability Access APIs component Reporter Mozilla Impact high References Bug 2061327 #CVE-2026-92017: Privilege escalation in the DOM: Service Workers component Reporter Mozilla Impact high References Bug 2061777 #CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component Reporter Quy Pham Impact high References Bug 2064287 #CVE-2026-92019: Mitigation bypass in the Remote Settings Client component Reporter Shu Takahashi Impact high References Bug 2065636 #CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component Reporter Rintaro Kawasugi Impact high References Bug 2066329 #CVE-2026-92021: Use-after-free in the JavaScript Engine: JIT component Reporter Tomer Fichman Impact high References Bug 2067208 #CVE-2026-92022: Use-after-free in the DOM: HTML Parser component Reporter Seohyeon Maeng Impact high References Bug 2068059 #CVE-2026-92023: Use-after-free in the XML component Reporter Mozilla Impact high References Bug 2068342 #CVE-2026-92024: Use-after-free in the SVG component Reporter Mozilla Impact high References Bug 2068354 #CVE-2026-92025: Use-after-free in the DOM: Navigation component Reporter Mozilla Impact high References Bug 2068361 #CVE-2026-92026: Use-after-free in the Networking component Reporter Mozilla Impact high References Bug 2068378 #CVE-2026-92027: Use-after-free in the DOM: Streams component Reporter Mozilla Impact high References Bug 2068433 #CVE-2026-92028: Use-after-free in the DOM: Core & HTML component Reporter Mozilla Impact high References Bug 2068440 #CVE-2026-92029: Use-after-free in the SVG component Reporter Mozilla Impact high References Bug 2068445 #CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component Reporter anas cherni Impact moderate References Bug 2058417 #CVE-2026-92031: Information disclosure in the Graphics: ImageLib component Reporter Qi Qin Impact moderate References Bug 2067971 #CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component Reporter Mozilla Impact moderate References Bug 2068437 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.21 2026/09/01 16:02:34 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.16.0esr.source.tar.xz) = 787602619860678dbde4ff0ebe59db1f2a0920835b9fe6a523ac8ff7947b04d2 SHA512 (firefox-140.16.0esr.source.tar.xz) = fabf5b481594a9a860b6ae379d2ee89ba291b807c94334ee15bad1fe862edb47c22e890d892e33d6a6ec57fce4ab12aa9c9c6fa4a501b881ecc6211ac04bd9a0 Size (firefox-140.16.0esr.source.tar.xz) = 632581380 bytes @ 1.21 log @firefox140: update to 140.15 Mozilla Foundation Security Advisory 2026-84 Security Vulnerabilities fixed in Firefox ESR 140.15 Announced September 1, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.15 #CVE-2026-75874: Sandbox escape in the Remote Settings Client component Reporter crixer Impact high References Bug 2039972 #CVE-2026-16365: Privilege escalation in the DOM: Workers component Reporter Khanh Nguyen Impact high References Bug 2049149 #CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component Reporter Yaqoub Aldurayhim Impact high References Bug 2057817 #CVE-2026-84120: Use-after-free in the Audio/Video component Reporter Ukyo Akai Impact high References Bug 2058911 #CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component Reporter Yaqoub Aldurayhim Impact high References Bug 2059018 #CVE-2026-84122: Use-after-free in the Audio/Video component Reporter Hyeonjun Ahn Impact high References Bug 2059965 #CVE-2026-84124: Use-after-free in the DOM: Core & HTML component Reporter Hyeonjun Ahn Impact high References Bug 2061110 #CVE-2026-16371: Privilege escalation in the DOM: Navigation component Reporter Steven Julian Impact moderate References Bug 2008369 #CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component Reporter navapon Impact moderate References Bug 2060008 #CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 Reporter Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team Impact high Description Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Firefox ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. References High Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 Moderate Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 Low Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 #CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 Reporter Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team Impact high Description Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. References High Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 Moderate Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 Low Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.20 2026/08/19 02:36:12 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.15.0esr.source.tar.xz) = 6a82557345fb1b797bea278dd84fda29fcb4c19be1f579c08b082a3b3b191b78 SHA512 (firefox-140.15.0esr.source.tar.xz) = c3a9c92776fc0fe4ec84e83d608822a84ab424bef3e9200de8e17f161369d13bb4a5caf5de326dded23edaf1c6b424d831218029786d4cfd1d857ee2634efeff Size (firefox-140.15.0esr.source.tar.xz) = 640054332 bytes @ 1.20 log @firefox140: update to 140.14 Mozilla Foundation Security Advisory 2026-76 Security Vulnerabilities fixed in Firefox ESR 140.14 Announced August 18, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.14 #CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component Reporter satyamasd Impact high References Bug 2050584 #CVE-2026-74935: Privilege escalation in the DOM: Networking component Reporter Yaqoub Aldurayhim Impact high References Bug 2051013 #CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component Reporter Amy Burnett of OpenAI Impact high References Bug 2052688 #CVE-2026-74939: Privilege escalation in the DOM: Navigation component Reporter choeseyeong Impact high References Bug 2054416 #CVE-2026-74940: Use-after-free in the Graphics: Text component Reporter kiyong Impact high References Bug 2054842 #CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component Reporter Jacolon Walker Impact high References Bug 2055056 #CVE-2026-74942: Privilege escalation in the Remote Settings Client component Reporter Gal Ankonina Impact high References Bug 2056571 #CVE-2026-74943: Use-after-free in the Graphics: ImageLib component Reporter Abdulaziz Alasaiqah Impact high References Bug 2057308 #CVE-2026-74944: Use-after-free in the DOM: Core & HTML component Reporter Amy Burnett of OpenAI Impact high References Bug 2057778 #CVE-2026-74945: Information disclosure in the Graphics: Text component Reporter Abdulaziz Alasaiqah Impact high References Bug 2057808 #CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter locust1b Impact high References Bug 2059997 #CVE-2026-74948: Information disclosure in the Graphics component Reporter Yaqoub Aldurayhim Impact high References Bug 2060106 #CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component Reporter r00tdaddy Impact high References Bug 2060245 #CVE-2026-74953: Privilege escalation in the Networking: Cookies component Reporter Satoki Tsuji Impact moderate References Bug 2022382 #CVE-2026-74957: Mitigation bypass in the Safe Browsing component Reporter Tomoya Nakanishi Impact moderate References Bug 2041906 #CVE-2026-74959: Mitigation bypass in the Storage: Cache API component Reporter David Bors at Snyk Security Labs Impact moderate References Bug 2047853 #CVE-2026-74960: Site isolation issue in the WebExtensions component Reporter Khanh Nguyen Impact moderate References Bug 2049148 #CVE-2026-74962: Site isolation issue in the Networking: Cookies component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2050425 #CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component Reporter 5up3rh3i Impact moderate References Bug 2050482 #CVE-2026-74964: Integer overflow in the Graphics component Reporter 5up3rh3i Impact moderate References Bug 2053327 #CVE-2026-74965: Privilege escalation in the Shell Integration component Reporter Khanh Nguyen Impact moderate References Bug 2053455 #CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component Reporter The Mozilla Fuzzing Team Impact moderate References Bug 2055697 #CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component Reporter Hyeonjun Ahn Impact moderate References Bug 2056065 #CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component Reporter avlidienbrunn Impact moderate References Bug 2057204 #CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component Reporter Kagami Rosylight Impact moderate References Bug 2059053 #CVE-2026-74973: Race condition, use-after-free in the Graphics component Reporter r00tdaddy Impact moderate References Bug 2060357 #CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component Reporter The Mozilla Fuzzing Team Impact moderate References Bug 2061794 #CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component Reporter anbu Impact low References Bug 1952164 #CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component Reporter 5up3rh3i Impact low References Bug 2051897 #CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Reporter Nicolas Silva, Tom Ritter and the Mozilla Fuzzing Team Impact high Description Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. References High Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Moderate Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Low Severity internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 #CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Reporter Christian Holler, Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team Impact high Description Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. References High Severity internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Moderate Severity internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.19 2026/07/21 16:30:32 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.14.0esr.source.tar.xz) = 6e444488cfb0cd6c0ec8dbcc7328916fcf2b9ef09ec327886a7116cd3a7c54cb SHA512 (firefox-140.14.0esr.source.tar.xz) = 0609cca9bfaecbff56cdf13458534bd8cfa43f139056867d3b6394a767281599ee600f83165ad25565ced59b552592aa84431357458ccecfbe5bf104dca501c7 Size (firefox-140.14.0esr.source.tar.xz) = 643083928 bytes @ 1.19 log @firefox140: update to 140.13 Mozilla Foundation Security Advisory 2026-70 Security Vulnerabilities fixed in Firefox ESR 140.13 Announced July 21, 2026 Impact critical Products Firefox ESR Fixed in Firefox ESR 140.13 #CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component Reporter Christian Holler Impact critical Description We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. References Bug 2045443 #CVE-2026-15719: Site isolation issue in the DOM: Navigation component Reporter Atsushi Sada Impact critical Description We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. References Bug 2043820 #CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component Reporter Tran Quac Impact high References Bug 2034682 #CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component Reporter Tomoya Nakanishi Impact high References Bug 2042033 #CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component Reporter crixer Impact high References Bug 2043188 #CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component Reporter Yaqoub Aldurayhim Impact high References Bug 2045468 #CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component Reporter Oskar L Impact high References Bug 2046416 #CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component Reporter Nebula Security Impact high References Bug 2047689 #CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component Reporter fedek Impact high References Bug 2049523 #CVE-2026-16354: Information disclosure in the Graphics: ImageLib component Reporter satyamasd Impact high References Bug 2050626 #CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component Reporter Nebula Security Impact high References Bug 2051015 #CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component Reporter Amy Burnett of OpenAI Impact high References Bug 2051854 #CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component Reporter Amy Burnett of OpenAI Impact high References Bug 2052207 #CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component Reporter Oskar L Impact high References Bug 2052562 #CVE-2026-16357: Incorrect boundary conditions in the Graphics component Reporter 5up3rh3i Impact high References Bug 2053326 #CVE-2026-16371: Privilege escalation in the DOM: Navigation component Reporter stevej Impact moderate References Bug 2008369 #CVE-2026-16374: Information disclosure in the Framework component in DevTools Reporter Tomoya Nakanishi Impact moderate References Bug 2027519 #CVE-2026-16375: Site isolation issue in the Networking: HTTP component Reporter pakhunov.anton.n Impact moderate References Bug 2032140 #CVE-2026-16377: Mitigation bypass in the PDF Viewer component Reporter Nikola Kojic Impact moderate References Bug 2037770 #CVE-2026-16379: Privilege escalation in the DOM: Content Processes component Reporter Shu Takahashi Impact moderate References Bug 2039452 #CVE-2026-16358: Site isolation issue in the Graphics: WebRender component Reporter Hcamael Impact moderate References Bug 2040119 #CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component Reporter Rintaro Kawasugi Impact moderate References Bug 2041001 #CVE-2026-16383: Mitigation bypass in the DOM: Networking component Reporter Ibuki Sato and Tomoya Nakanishi Impact moderate References Bug 2041902 #CVE-2026-16387: Site isolation issue in the Networking component Reporter Atsushi Sada Impact moderate References Bug 2043200 #CVE-2026-16390: Mitigation bypass in the Enterprise Policies component Reporter Souma Ohsawa Impact moderate References Bug 2044527 #CVE-2026-16391: Information disclosure in the Storage: IndexedDB component Reporter Tomoya Nakanishi Impact moderate References Bug 2044536 #CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component Reporter Jacolon Walker Impact moderate References Bug 2045424 #CVE-2026-16396: Privilege escalation in WebExtensions Reporter Quy Pham Impact moderate References Bug 2047240 #CVE-2026-16405: Information disclosure in the Networking: WebSockets component Reporter Yaqoub Aldurayhim Impact low References Bug 2036591 #CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 Reporter Christian Holler, Frederik Braun, Justin Link, Simon Friedberger, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References High-severity memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 Moderate-severity memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 Low-severity memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 #CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 Reporter Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References High-severity memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 Moderate-severity memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 #CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 Reporter The Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References High-severity memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.18 2026/06/16 16:16:43 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.13.0esr.source.tar.xz) = ea85681fc369dc74f8637b1182840a2c3be8dc94bfbb5666e7bf53f46625cf9e SHA512 (firefox-140.13.0esr.source.tar.xz) = 937a4103d71c5e1e4bf051821729f6ea70b5c18d444930a487695cc23d74712a0134047248f6ac02305e01becb705426a55b9d89739f02a01eda01ecf5bc27f1 Size (firefox-140.13.0esr.source.tar.xz) = 644768324 bytes @ 1.18 log @firefox140: update to 140.12 Update during freeze approved by maya@@. Mozilla Foundation Security Advisory 2026-58 Security Vulnerabilities fixed in Firefox ESR 140.12 Announced June 16, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.12 #CVE-2026-12289: Privilege escalation in the Graphics: WebRender component Reporter choeseyeong Impact high References Bug 2023443 #CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12 Reporter jayjayjazz Impact high References Bug 2024852 #CVE-2026-12291: Use-after-free in the Networking: HTTP component Reporter Zijie Zhao Impact high References Bug 2036929 #CVE-2026-12292: Incorrect boundary conditions in the Web Audio component Reporter Zijie Zhao Impact high References Bug 2038465 #CVE-2026-12294: Sandbox escape in the DOM: Workers component Reporter Quy Pham Impact high References Bug 2039873 #CVE-2026-12295: Sandbox escape in the DOM: Navigation component Reporter Yaqoub Aldurayhim Impact high References Bug 2040160 #CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12 Reporter Haruka Yamazaki Impact high References Bug 2041981 #CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component Reporter Yaqoub Aldurayhim Impact high References Bug 2040515 #CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component Reporter zx Impact high References Bug 2041610 #CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component Reporter Hyeonjun Ahn Impact high References Bug 2043139 #CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12 Reporter Michael Froman Impact high References Bug 2044738 #CVE-2026-12302: Mitigation bypass in the DOM: Security component Reporter lebr0nli Impact moderate References Bug 2034489 #CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2034944 #CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12 Reporter Zijie Zhao Impact moderate References Bug 2037290 #CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12 Reporter Mihalis Haatainen Impact moderate References Bug 2037323 #CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12 Reporter Atsushi Sada Impact moderate References Bug 2038133 #CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12 Reporter Mihalis Haatainen Impact moderate References Bug 2038302 #CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12 Reporter Yaqoub Aldurayhim Impact moderate References Bug 2038476 #CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12 Reporter Carl Pearson Impact moderate References Bug 2039707 #CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2040177 #CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12 Reporter Rintaro Kawasugi Impact moderate References Bug 2040383 #CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component Reporter evyatar Impact moderate References Bug 2040477 #CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12 Reporter satyamasd Impact moderate References Bug 2041856 #CVE-2026-12315: Mitigation bypass in the DOM: Security component Reporter Nguyen Minh Impact moderate References Bug 2042058 #CVE-2026-12330: Incorrect boundary conditions in the Internationalization component Reporter Mozilla Fuzzing Team Impact moderate References Bug 2029326 #CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Mihalis Haatainen Impact low References Bug 2038444 #CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component Reporter Securin Impact low References Bug 2039443 #CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 Reporter Christian Holler, Jens Stutte, Nika Layzell, Randell Jesup, Tom Schuster and the Mozilla Fuzzing Team Impact moderate Description Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Moderate Severity memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 #CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 Reporter Andrew McCreight, Randell Jesup, Tom Ritter and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References High Severity memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.17 2026/05/21 15:34:06 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.12.0esr.source.tar.xz) = 5aa6d7e2025eda47afca489720e6511c9aa29875699d021fc03068eaeb2b1486 SHA512 (firefox-140.12.0esr.source.tar.xz) = 3d598dd964bca074d11b71f84d586811b0a736bdd4d1e6cedb9286c56b1e11584e85ca1d0369c9b2f8d9e4d0eaf014d1b9232a96e71ac25f71fa9ed0807f642d Size (firefox-140.12.0esr.source.tar.xz) = 641934156 bytes @ 1.18.2.1 log @Pullup ticket #7190 - requested by gutteridge www/firefox140-l10n: Security fix www/firefox140: Security fix Revisions pulled up: - www/firefox140-l10n/Makefile 1.14 - www/firefox140-l10n/distinfo 1.14 - www/firefox140/Makefile 1.21 - www/firefox140/distinfo 1.19 --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Jul 21 16:30:32 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Log Message: firefox140: update to 140.13 Mozilla Foundation Security Advisory 2026-70 Security Vulnerabilities fixed in Firefox ESR 140.13 Announced July 21, 2026 Impact critical Products Firefox ESR Fixed in Firefox ESR 140.13 #CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component Reporter Christian Holler Impact critical Description We are aware that exploit code for this is public however we are not aware = of any attacks in the wild abusing this flaw. References Bug 2045443 #CVE-2026-15719: Site isolation issue in the DOM: Navigation component Reporter Atsushi Sada Impact critical Description We are aware that exploit code for this is public however we are not aware = of any attacks in the wild abusing this flaw. References Bug 2043820 #CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component Reporter Tran Quac Impact high References Bug 2034682 #CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb co= mponent Reporter Tomoya Nakanishi Impact high References Bug 2042033 #CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component Reporter crixer Impact high References Bug 2043188 #CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigatio= n component Reporter Yaqoub Aldurayhim Impact high References Bug 2045468 #CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Acc= ess APIs component Reporter Oskar L Impact high References Bug 2046416 #CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly componen= t Reporter Nebula Security Impact high References Bug 2047689 #CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component Reporter fedek Impact high References Bug 2049523 #CVE-2026-16354: Information disclosure in the Graphics: ImageLib component Reporter satyamasd Impact high References Bug 2050626 #CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssemb= ly component Reporter Nebula Security Impact high References Bug 2051015 #CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component Reporter Amy Burnett of OpenAI Impact high References Bug 2051854 #CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component Reporter Amy Burnett of OpenAI Impact high References Bug 2052207 #CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Acc= ess APIs component Reporter Oskar L Impact high References Bug 2052562 #CVE-2026-16357: Incorrect boundary conditions in the Graphics component Reporter 5up3rh3i Impact high References Bug 2053326 #CVE-2026-16371: Privilege escalation in the DOM: Navigation component Reporter stevej Impact moderate References Bug 2008369 #CVE-2026-16374: Information disclosure in the Framework component in DevTo= ols Reporter Tomoya Nakanishi Impact moderate References Bug 2027519 #CVE-2026-16375: Site isolation issue in the Networking: HTTP component Reporter pakhunov.anton.n Impact moderate References Bug 2032140 #CVE-2026-16377: Mitigation bypass in the PDF Viewer component Reporter Nikola Kojic Impact moderate References Bug 2037770 #CVE-2026-16379: Privilege escalation in the DOM: Content Processes compone= nt Reporter Shu Takahashi Impact moderate References Bug 2039452 #CVE-2026-16358: Site isolation issue in the Graphics: WebRender component Reporter Hcamael Impact moderate References Bug 2040119 #CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component Reporter Rintaro Kawasugi Impact moderate References Bug 2041001 #CVE-2026-16383: Mitigation bypass in the DOM: Networking component Reporter Ibuki Sato and Tomoya Nakanishi Impact moderate References Bug 2041902 #CVE-2026-16387: Site isolation issue in the Networking component Reporter Atsushi Sada Impact moderate References Bug 2043200 #CVE-2026-16390: Mitigation bypass in the Enterprise Policies component Reporter Souma Ohsawa Impact moderate References Bug 2044527 #CVE-2026-16391: Information disclosure in the Storage: IndexedDB component Reporter Tomoya Nakanishi Impact moderate References Bug 2044536 #CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP comp= onent Reporter Jacolon Walker Impact moderate References Bug 2045424 #CVE-2026-16396: Privilege escalation in WebExtensions Reporter Quy Pham Impact moderate References Bug 2047240 #CVE-2026-16405: Information disclosure in the Networking: WebSockets compo= nent Reporter Yaqoub Aldurayhim Impact low References Bug 2036591 #CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox= 153 Reporter Christian Holler, Frederik Braun, Justin Link, Simon Friedberger, Tom R= itter, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of t= hese bugs showed evidence of memory corruption and we presume that with eno= ugh effort some of these could have been=20 exploited to run arbitrary code. References High-severity memory safety bugs fixed in Firefox ESR 140.13 and Firefo= x 153 Moderate-severity memory safety bugs fixed in Firefox ESR 140.13 and Fi= refox 153 Low-severity memory safety bugs fixed in Firefox ESR 140.13 and Firefox= 153 #CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ES= R 140.13 and Firefox 153 Reporter Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla and the Mozil= la Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Fi= refox 152. Some of these bugs showed evidence of memory corruption and we p= resume that with enough effort some of these=20 could have been exploited to run arbitrary code. References High-severity memory safety bugs fixed in Firefox ESR 115.38, Firefox E= SR 140.13 and Firefox 153 Moderate-severity memory safety bugs fixed in Firefox ESR 115.38, Firef= ox ESR 140.13 and Firefox 153 #CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox= ESR 140.13 Reporter The Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. So= me of these bugs showed evidence of memory corruption and we presume that w= ith enough effort some of these could have been=20 exploited to run arbitrary code. References High-severity memory safety bugs fixed in Firefox ESR 115.38 and Firefo= x ESR 140.13 --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Jul 21 16:31:06 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.13 @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (firefox-140.13.0esr.source.tar.xz) = ea85681fc369dc74f8637b1182840a2c3be8dc94bfbb5666e7bf53f46625cf9e SHA512 (firefox-140.13.0esr.source.tar.xz) = 937a4103d71c5e1e4bf051821729f6ea70b5c18d444930a487695cc23d74712a0134047248f6ac02305e01becb705426a55b9d89739f02a01eda01ecf5bc27f1 Size (firefox-140.13.0esr.source.tar.xz) = 644768324 bytes @ 1.18.2.2 log @Pullup ticket #7240 - requested by gutteridge www/firefox140: Security fix www/firefox140-l10n: Security fix Revisions pulled up: - www/firefox140-l10n/Makefile 1.15 - www/firefox140-l10n/distinfo 1.15 - www/firefox140/Makefile 1.22 - www/firefox140/distinfo 1.20 --- Module Name: pkgsrc Committed By: gutteridge Date: Wed Aug 19 02:36:12 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Log Message: firefox140: update to 140.14 --- Module Name: pkgsrc Committed By: gutteridge Date: Wed Aug 19 02:39:00 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.14 @ text @d3 3 a5 3 BLAKE2s (firefox-140.14.0esr.source.tar.xz) = 6e444488cfb0cd6c0ec8dbcc7328916fcf2b9ef09ec327886a7116cd3a7c54cb SHA512 (firefox-140.14.0esr.source.tar.xz) = 0609cca9bfaecbff56cdf13458534bd8cfa43f139056867d3b6394a767281599ee600f83165ad25565ced59b552592aa84431357458ccecfbe5bf104dca501c7 Size (firefox-140.14.0esr.source.tar.xz) = 643083928 bytes @ 1.17 log @firefox140: update to 140.11 Mozilla Foundation Security Advisory 2026-48 Security Vulnerabilities fixed in Firefox ESR 140.11 Announced May 19, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.11 #CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component Reporter zx Impact high References Bug 2029070 #CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component Reporter ggwhyp Impact high References Bug 2036978 #CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component Reporter Satoki Tsuji Impact high References Bug 2038439 #CVE-2026-8391: Other issue in the JavaScript Engine component Reporter ggwhyp Impact high References Bug 2038575 #CVE-2026-8401: Sandbox escape in the Profile Backup component Reporter ggwhyp Impact high References Bug 2038679 #CVE-2026-8949: Integer overflow in the Widget: Win32 component Reporter q1 Impact moderate References Bug 1355639 #CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component Reporter Jakub Szymsza Impact moderate References Bug 1965430 #CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component Reporter stevej Impact moderate References Bug 2029511 #CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component Reporter Ameen Basha M K Impact moderate References Bug 2030747 #CVE-2026-8955: Privilege escalation in the DOM: Workers component Reporter lebr0nli Impact moderate References Bug 2031064 #CVE-2026-8956: Integer overflow in the Networking: JAR component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2032427 #CVE-2026-8957: Privilege escalation in the Enterprise Policies component Reporter Mateusz Dobrzyński Impact moderate References Bug 2033850 #CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2034713 #CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component Reporter Ameen Basha M K Impact moderate References Bug 2034754 #CVE-2026-8961: Spoofing issue in the Form Autofill component Reporter Hafiizh Impact low References Bug 1962625 #CVE-2026-8962: Mitigation bypass in the DOM: Security component Reporter Manojkumar Jaganathan Impact low References Bug 2004804 #CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component Reporter Tristan Madani Impact low References Bug 2030467 #CVE-2026-8970: Privilege escalation in the Security component Reporter pakhunov.anton.n Impact low References Bug 2032174 #CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 Reporter Nika Layzell, Randell Jesup, Timothy Nikkel, Tom Schuster and the Mozilla Fuzzing Team Impact moderate Description Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 #CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 Reporter Andrew McCreight, Valentin Gosu, Nika Layzell, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.16 2026/05/07 20:25:32 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.11.0esr.source.tar.xz) = 567b3ce95be1e3809dbd1d4e36a9b4fed544bd4b8e3bf24fff238daf0743bfaf SHA512 (firefox-140.11.0esr.source.tar.xz) = d06adb3ef4de1324e3d61872d70de31ab08ac013f33903549bed28c6ebcc5b4dee94bb36388282c1935d77d1a564079f3adbf08d6bb80284a899cbb3d861300c Size (firefox-140.11.0esr.source.tar.xz) = 637083992 bytes @ 1.16 log @firefox140: update to 140.10.2 Mozilla Foundation Security Advisory 2026-41 Security Vulnerabilities fixed in Firefox ESR 140.10.2 Announced May 7, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.10.2 #CVE-2026-8090: Use-after-free in the DOM: Networking component Reporter Kevin Brosnan Impact high References Bug 2034352 #CVE-2026-8094: Other issue in the WebRTC component Reporter Michael Froman Impact high References Bug 2035939 #CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 Reporter Andrew McCreight, Christian Holler, Lee Salzman, Maurice Dauer, Tom Schuster, Wayne Mery and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.15 2026/04/30 21:47:25 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.10.2esr.source.tar.xz) = e8ccac19f20030271519ca34b325ee152f6f53f8343bea5b4c1cf1359a63aa4c SHA512 (firefox-140.10.2esr.source.tar.xz) = bda7d5e6d59a2ad310e3f3e6e8ec05c78222edce266671d5d454dfa3e8f0086add3b9c0099db907cb62b2587ed47026ba7b3aa4f0406693d142d8d91b818d551 Size (firefox-140.10.2esr.source.tar.xz) = 638783848 bytes a28 1 SHA1 (patch-media_ffvpx_libavcodec_parser__list.c) = 3965eb52df3e0821807ddf258c1209a2dd636104 @ 1.15 log @firefox140: note new patch added was already fixed upstream @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.14 2026/04/30 18:51:22 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.10.1esr.source.tar.xz) = c1ff3f87a5fe9357dafc87c008d6b2ada6dab049808e9be258f6dda37d44222a SHA512 (firefox-140.10.1esr.source.tar.xz) = aa3481dbdda0a302acefff52007ba2e6927962523408b942a7df673e80618fc381faf1ca70ebaac3760645bf7cb382b85658af49beca705cd636ce9de58349a5 Size (firefox-140.10.1esr.source.tar.xz) = 638929340 bytes @ 1.14 log @firefox140: update to 140.10.1 Mozilla Foundation Security Advisory 2026-36 Security Vulnerabilities fixed in Firefox ESR 140.10.1 Announced April 28, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.10.1 #CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component Reporter Xuehao Guo Impact high References Bug 2027433 #CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component Reporter The Mozilla Fuzzing Team Impact moderate References Bug 2029461 #CVE-2026-7322: Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1 Reporter C.M.Chang, Christian Holler, Steve Fink and the Mozilla Fuzzing Team Impact critical Description Memory safety bugs present in Firefox ESR 115.35.0, Firefox ESR 140.10.0 and Firefox 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1 #CVE-2026-7323: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1 Reporter Ryan Hunt, Steve Fink and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.10.0 and Firefox 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.13 2026/04/21 13:40:08 gutteridge Exp $ d29 1 a29 1 SHA1 (patch-media_ffvpx_libavcodec_parser__list.c) = c739791026d9ea3ef2ccc1c37db9edc37635e8d4 @ 1.13 log @firefox140: update to 140.10 Mozilla Foundation Security Advisory 2026-32 Security Vulnerabilities fixed in Firefox ESR 140.10 Announced April 21, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.10 #CVE-2026-6746: Use-after-free in the DOM: Core & HTML component Reporter Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic Impact high References Bug 2014596 #CVE-2026-6747: Use-after-free in the WebRTC component Reporter Nan Wang Impact high References Bug 2021769 #CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component Reporter Inseo An Impact high References Bug 2022604 #CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component Reporter Inseo An Impact high References Bug 2022610 #CVE-2026-6750: Privilege escalation in the Graphics: WebRender component Reporter choeseyeong Impact high References Bug 2023407 #CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component Reporter Joren Afman Impact high References Bug 2025883 #CVE-2026-6752: Incorrect boundary conditions in the WebRTC component Reporter jmwebdevelopement Impact high References Bug 2027499 #CVE-2026-6753: Incorrect boundary conditions in the WebRTC component Reporter jmwebdevelopement Impact high References Bug 2027501 #CVE-2026-6754: Use-after-free in the JavaScript Engine component Reporter Xuehao Guo Impact high References Bug 2027541 #CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component Reporter Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic Impact moderate References Bug 2013588 #CVE-2026-6759: Use-after-free in the Widget: Cocoa component Reporter Steven Michaud Impact moderate References Bug 2016164 #CVE-2026-6761: Privilege escalation in the Networking component Reporter kiyong Impact moderate References Bug 2017857 #CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component Reporter Farras Givari Impact moderate References Bug 2021080 #CVE-2026-6763: Mitigation bypass in the File Handling component Reporter Tomoya Nakanishi Impact moderate References Bug 2021666 #CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component Reporter Florian Impact moderate References Bug 2022162 #CVE-2026-6765: Information disclosure in the Form Autofill component Reporter ABDULAZIZ ALASAIQAH Impact moderate References Bug 2022419 #CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS Reporter Haruto Kimura Impact moderate References Bug 2023207 #CVE-2026-6767: Other issue in the Libraries component in NSS Reporter Haruto Kimura Impact moderate References Bug 2023209 #CVE-2026-6769: Privilege escalation in the Debugger component Reporter Tomoya Nakanishi Impact moderate References Bug 2023753 #CVE-2026-6770: Other issue in the Storage: IndexedDB component Reporter Dai Impact moderate References Bug 2024220 #CVE-2026-6771: Mitigation bypass in the DOM: Security component Reporter Rayhan Hanaputra Impact moderate References Bug 2025067 #CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS Reporter sseehra Impact moderate References Bug 2026089 #CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component Reporter Nan Wang Impact low References Bug 2021770 #CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 Reporter Andrew McCreight, Ashley Zebrowski, Brian Grinstead, Christian Holler, Maurice Dauer, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 #CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 Reporter Alex Franchuk, Andrew McCreight, Brian Grinstead, Christian Holler, Jan de Mooij, Maurice Dauer, Sebastian Hengst, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.12 2026/04/09 18:37:06 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.10.0esr.source.tar.xz) = 94fea47829730dbdb974dfdd694d214a86de37f21bf6a6aa98437f34e410c5ee SHA512 (firefox-140.10.0esr.source.tar.xz) = 56b274df21d0a908e826af6dda89a42b77fb0f597b75542b0330d448ae22be07a3636a3187ff1b488e466cc8c5264a8a75f79901354a49e35a3e99dcb0852514 Size (firefox-140.10.0esr.source.tar.xz) = 636605480 bytes d29 1 @ 1.12 log @firefox140: update to 140.9.1 Mozilla Foundation Security Advisory 2026-27 Security Vulnerabilities fixed in Firefox ESR 140.9.1 Announced April 7, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.9.1 #CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Graphics: Text component Reporter Sajeeb Lohani Impact high References Bug 2017867 #CVE-2026-5731: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 Reporter Brian Grinstead, Christian Holler, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 #CVE-2026-5734: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 Reporter Brian Grinstead, Christian Holler, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.11 2026/03/24 13:11:35 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.9.1esr.source.tar.xz) = 0602c185e37132155cbd4b9bc9b795295b99bc81eb2bf7c282bf5b29b21aa0d9 SHA512 (firefox-140.9.1esr.source.tar.xz) = 119a4e4e536fd4534adcc4a546a988e553285f9326bf16e9771854ec2dc7d039a729aedc5925623e172260a5e154172c56a011f131068736eb2a89a8de611840 Size (firefox-140.9.1esr.source.tar.xz) = 634745800 bytes @ 1.11 log @firefox140: update to 140.9 Mozilla Foundation Security Advisory 2026-22 Security Vulnerabilities fixed in Firefox ESR 140.9 Announced March 24, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.9 #CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component Reporter Oskar L Impact high References Bug 2011129 #CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component Reporter Sajeeb Lohani Impact high References Bug 2016349 #CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component Reporter Sajeeb Lohani Impact high References Bug 2016351 #CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component Reporter Sajeeb Lohani Impact high References Bug 2016368 #CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component Reporter Sajeeb Lohani Impact high References Bug 2016373 #CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component Reporter Sajeeb Lohani Impact high References Bug 2016374 #CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component Reporter Sajeeb Lohani Impact high References Bug 2016375 #CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component Reporter Fabius Artrel Impact high References Bug 2017512 #CVE-2026-4692: Sandbox escape in the Responsive Design Mode component Reporter Tom Ritter Impact high References Bug 2017643 #CVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component Reporter Sajeeb Lohani Impact high References Bug 2018102 #CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component Reporter Sajeeb Lohani Impact high References Bug 2018430 #CVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component Reporter Atte Kettunen Impact high References Bug 2020030 #CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component Reporter Sota Wada Impact high References Bug 2020190 #CVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component Reporter Lorenzo Impact high References Bug 2020422 #CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component Reporter maxpl0it working with Trend Micro Zero Day Initiative Impact high References Bug 2020906 #CVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component Reporter Matej Smycka Impact high References Bug 2021863 #CVE-2026-4700: Mitigation bypass in the Networking: HTTP component Reporter pizzahunthack1 Impact moderate References Bug 2003766 #CVE-2026-4701: Use-after-free in the JavaScript Engine component Reporter Gary Kwong Impact moderate References Bug 2009303 #CVE-2026-4702: JIT miscompilation in the JavaScript Engine component Reporter Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic Impact moderate References Bug 2013560 #CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component Reporter Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic Impact moderate References Bug 2014868 #CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component Reporter Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic Impact moderate References Bug 2014873 #CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component Reporter Jun Yang Impact moderate References Bug 2015091 #CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component Reporter Sajeeb Lohani Impact moderate References Bug 2015267 #CVE-2026-4708: Incorrect boundary conditions in the Graphics component Reporter Sajeeb Lohani Impact moderate References Bug 2015268 #CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component Reporter Sajeeb Lohani Impact moderate References Bug 2016329 #CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component Reporter Sajeeb Lohani Impact moderate References Bug 2016370 #CVE-2026-4711: Use-after-free in the Widget: Cocoa component Reporter Josh Aas Impact moderate References Bug 2017002 #CVE-2026-4712: Information disclosure in the Widget: Cocoa component Reporter Josh Aas Impact moderate References Bug 2017666 #CVE-2026-4713: Incorrect boundary conditions in the Graphics component Reporter Sajeeb Lohani Impact moderate References Bug 2018113 #CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component Reporter Sajeeb Lohani Impact moderate References Bug 2018126 #CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component Reporter Jun Yang Impact moderate References Bug 2018405 #CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component Reporter Pwn2addr Impact moderate References Bug 2018592 #CVE-2026-4717: Privilege escalation in the Netmonitor component Reporter Satoki Tsuji Impact moderate References Bug 2021695 #CVE-2025-59375: Denial-of-service in the XML component Reporter Jan Horak Impact low References Bug 1988467 #CVE-2026-4718: Undefined behavior in the WebRTC: Signaling component Reporter Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic Impact low References Bug 2014864 #CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component Reporter Sajeeb Lohani Impact low References Bug 2016367 #CVE-2026-4720: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 Reporter Christian Holler, Gabriele Svelto, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 #CVE-2026-4721: Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 Reporter Christian Holler, Timothy Nikkel, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.10 2026/02/24 14:07:55 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.9.0esr.source.tar.xz) = 75f692405065815d77747a641f067694ec99a82548df0f326dada4f6963ccfa7 SHA512 (firefox-140.9.0esr.source.tar.xz) = bc03fd2a73d00a88bd0a3c9eeaefe618ffb34226fb7bc2fac4a02246ff29fe038423bf77538273ee6fac25fb1e3e4fa98bb522026ae3427a0ad5f41d2ec6ba98 Size (firefox-140.9.0esr.source.tar.xz) = 630445704 bytes @ 1.11.2.1 log @Pullup ticket #7074 - requested by gutteridge www/firefox140: security fix www/firefox140-l10n: dependent update Revisions pulled up: - www/firefox140-l10n/Makefile 1.8 - www/firefox140-l10n/distinfo 1.8 - www/firefox140/Makefile 1.13 - www/firefox140/distinfo 1.12 --- Module Name: pkgsrc Committed By: gutteridge Date: Thu Apr 9 18:37:06 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Log Message: firefox140: update to 140.9.1 Mozilla Foundation Security Advisory 2026-27 Security Vulnerabilities fixed in Firefox ESR 140.9.1 Announced April 7, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.9.1 #CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Grap= hics: Text component Reporter Sajeeb Lohani Impact high References Bug 2017867 #CVE-2026-5731: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox E= SR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.= 2 Reporter Brian Grinstead, Christian Holler, Tom Schuster and the Mozilla Fuzzing= Team Impact high Description Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Th= underbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of the= se bugs showed evidence of memory corruption and=20 we presume that with enough effort some of these could have been exploited = to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, = Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 #CVE-2026-5734: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbir= d ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 Reporter Brian Grinstead, Christian Holler, Tom Schuster and the Mozilla Fuzzing= Team Impact high Description Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0,= Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidenc= e of memory corruption and we presume that with=20 enough effort some of these could have been exploited to run arbitrary code= . References Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.= 1, Firefox 149.0.2 and Thunderbird 149.0.2 --- Module Name: pkgsrc Committed By: gutteridge Date: Thu Apr 9 18:39:26 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.9.1 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.11 2026/03/24 13:11:35 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.9.1esr.source.tar.xz) = 0602c185e37132155cbd4b9bc9b795295b99bc81eb2bf7c282bf5b29b21aa0d9 SHA512 (firefox-140.9.1esr.source.tar.xz) = 119a4e4e536fd4534adcc4a546a988e553285f9326bf16e9771854ec2dc7d039a729aedc5925623e172260a5e154172c56a011f131068736eb2a89a8de611840 Size (firefox-140.9.1esr.source.tar.xz) = 634745800 bytes @ 1.11.2.2 log @Revbump all Go packages after go126 security fix @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.4.2.2 2026/01/14 18:58:46 maya Exp $ @ 1.11.2.3 log @Pullup ticket #7083 - requested by gutteridge www/firefox140: security fix www/firefox140-l10n: dependent update Revisions pulled up: - www/firefox140-l10n/Makefile 1.9 - www/firefox140-l10n/distinfo 1.9 - www/firefox140/Makefile 1.14 - www/firefox140/distinfo 1.13 --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Apr 21 13:40:08 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Log Message: firefox140: update to 140.10 Mozilla Foundation Security Advisory 2026-32 Security Vulnerabilities fixed in Firefox ESR 140.10 Announced April 21, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.10 #CVE-2026-6746: Use-after-free in the DOM: Core & HTML component Reporter Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic Impact high References Bug 2014596 #CVE-2026-6747: Use-after-free in the WebRTC component Reporter Nan Wang Impact high References Bug 2021769 #CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component Reporter Inseo An Impact high References Bug 2022604 #CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component Reporter Inseo An Impact high References Bug 2022610 #CVE-2026-6750: Privilege escalation in the Graphics: WebRender component Reporter choeseyeong Impact high References Bug 2023407 #CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component Reporter Joren Afman Impact high References Bug 2025883 #CVE-2026-6752: Incorrect boundary conditions in the WebRTC component Reporter jmwebdevelopement Impact high References Bug 2027499 #CVE-2026-6753: Incorrect boundary conditions in the WebRTC component Reporter jmwebdevelopement Impact high References Bug 2027501 #CVE-2026-6754: Use-after-free in the JavaScript Engine component Reporter Xuehao Guo Impact high References Bug 2027541 #CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component Reporter Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic Impact moderate References Bug 2013588 #CVE-2026-6759: Use-after-free in the Widget: Cocoa component Reporter Steven Michaud Impact moderate References Bug 2016164 #CVE-2026-6761: Privilege escalation in the Networking component Reporter kiyong Impact moderate References Bug 2017857 #CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component Reporter Farras Givari Impact moderate References Bug 2021080 #CVE-2026-6763: Mitigation bypass in the File Handling component Reporter Tomoya Nakanishi Impact moderate References Bug 2021666 #CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component Reporter Florian Impact moderate References Bug 2022162 #CVE-2026-6765: Information disclosure in the Form Autofill component Reporter ABDULAZIZ ALASAIQAH Impact moderate References Bug 2022419 #CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS Reporter Haruto Kimura Impact moderate References Bug 2023207 #CVE-2026-6767: Other issue in the Libraries component in NSS Reporter Haruto Kimura Impact moderate References Bug 2023209 #CVE-2026-6769: Privilege escalation in the Debugger component Reporter Tomoya Nakanishi Impact moderate References Bug 2023753 #CVE-2026-6770: Other issue in the Storage: IndexedDB component Reporter Dai Impact moderate References Bug 2024220 #CVE-2026-6771: Mitigation bypass in the DOM: Security component Reporter Rayhan Hanaputra Impact moderate References Bug 2025067 #CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS Reporter sseehra Impact moderate References Bug 2026089 #CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component Reporter Nan Wang Impact low References Bug 2021770 #CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 Reporter Andrew McCreight, Ashley Zebrowski, Brian Grinstead, Christian Holler, Maurice Dauer, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 #CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 Reporter Alex Franchuk, Andrew McCreight, Brian Grinstead, Christian Holler, Jan de Mooij, Maurice Dauer, Sebastian Hengst, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Apr 21 13:42:06 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.10 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.11.2.2 2026/04/22 14:32:19 maya Exp $ d3 3 a5 3 BLAKE2s (firefox-140.10.0esr.source.tar.xz) = 94fea47829730dbdb974dfdd694d214a86de37f21bf6a6aa98437f34e410c5ee SHA512 (firefox-140.10.0esr.source.tar.xz) = 56b274df21d0a908e826af6dda89a42b77fb0f597b75542b0330d448ae22be07a3636a3187ff1b488e466cc8c5264a8a75f79901354a49e35a3e99dcb0852514 Size (firefox-140.10.0esr.source.tar.xz) = 636605480 bytes @ 1.11.2.4 log @Pullup ticket #7087 - requested by gutteridge www/firefox140: security fix www/firefox140-l10n: dependent update Revisions pulled up: - www/firefox140-l10n/Makefile 1.10 - www/firefox140-l10n/distinfo 1.10 - www/firefox140/Makefile 1.15 - www/firefox140/distinfo 1.14-1.15 - www/firefox140/patches/patch-media_ffvpx_libavcodec_parser__list.c 1.1-1.2 --- Module Name: pkgsrc Committed By: gutteridge Date: Thu Apr 30 18:51:23 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Added Files: pkgsrc/www/firefox140/patches: patch-media_ffvpx_libavcodec_parser__list.c Log Message: firefox140: update to 140.10.1 Mozilla Foundation Security Advisory 2026-36 Security Vulnerabilities fixed in Firefox ESR 140.10.1 Announced April 28, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.10.1 #CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component Reporter Xuehao Guo Impact high References Bug 2027433 #CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component Reporter The Mozilla Fuzzing Team Impact moderate References Bug 2029461 #CVE-2026-7322: Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1 Reporter C.M.Chang, Christian Holler, Steve Fink and the Mozilla Fuzzing Team Impact critical Description Memory safety bugs present in Firefox ESR 115.35.0, Firefox ESR 140.10.0 and Firefox 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1 #CVE-2026-7323: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1 Reporter Ryan Hunt, Steve Fink and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.10.0 and Firefox 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1 --- Module Name: pkgsrc Committed By: gutteridge Date: Thu Apr 30 18:53:28 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.10.1 --- Module Name: pkgsrc Committed By: gutteridge Date: Thu Apr 30 21:47:25 UTC 2026 Modified Files: pkgsrc/www/firefox140: distinfo pkgsrc/www/firefox140/patches: patch-media_ffvpx_libavcodec_parser__list.c Log Message: firefox140: note new patch added was already fixed upstream @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.11.2.3 2026/04/26 19:35:21 bsiegert Exp $ d3 3 a5 3 BLAKE2s (firefox-140.10.1esr.source.tar.xz) = c1ff3f87a5fe9357dafc87c008d6b2ada6dab049808e9be258f6dda37d44222a SHA512 (firefox-140.10.1esr.source.tar.xz) = aa3481dbdda0a302acefff52007ba2e6927962523408b942a7df673e80618fc381faf1ca70ebaac3760645bf7cb382b85658af49beca705cd636ce9de58349a5 Size (firefox-140.10.1esr.source.tar.xz) = 638929340 bytes a28 1 SHA1 (patch-media_ffvpx_libavcodec_parser__list.c) = 3965eb52df3e0821807ddf258c1209a2dd636104 @ 1.11.2.5 log @Pullup ticket #7102 - requested by gutteridge www/firefox140: Security fix www/firefox140-l10n: Security fix Revisions pulled up: - www/firefox140-l10n/Makefile 1.11 - www/firefox140-l10n/distinfo 1.11 - www/firefox140/Makefile 1.16 - www/firefox140/distinfo 1.16 --- Module Name: pkgsrc Committed By: gutteridge Date: Thu May 7 20:25:32 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Log Message: firefox140: update to 140.10.2 Mozilla Foundation Security Advisory 2026-41 Security Vulnerabilities fixed in Firefox ESR 140.10.2 Announced May 7, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.10.2 #CVE-2026-8090: Use-after-free in the DOM: Networking component Reporter Kevin Brosnan Impact high References Bug 2034352 #CVE-2026-8094: Other issue in the WebRTC component Reporter Michael Froman Impact high References Bug 2035939 #CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox E= SR 140.10.2 and Firefox 150.0.2 Reporter Andrew McCreight, Christian Holler, Lee Salzman, Maurice Dauer, Tom Sch= uster, Wayne Mery and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 an= d Firefox 150.0.1. Some of these bugs showed evidence of memory corruption = and we presume that with enough effort some of=20 these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 = and Firefox 150.0.2 --- Module Name: pkgsrc Committed By: gutteridge Date: Thu May 7 20:26:58 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.10.2 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.11.2.4 2026/05/02 19:26:59 bsiegert Exp $ d3 3 a5 3 BLAKE2s (firefox-140.10.2esr.source.tar.xz) = e8ccac19f20030271519ca34b325ee152f6f53f8343bea5b4c1cf1359a63aa4c SHA512 (firefox-140.10.2esr.source.tar.xz) = bda7d5e6d59a2ad310e3f3e6e8ec05c78222edce266671d5d454dfa3e8f0086add3b9c0099db907cb62b2587ed47026ba7b3aa4f0406693d142d8d91b818d551 Size (firefox-140.10.2esr.source.tar.xz) = 638783848 bytes @ 1.11.2.6 log @Pullup ticket #7127 - requested by gutteridge www/firefox140: security fix www/firefox140-l10n: dependent update Revisions pulled up: - www/firefox140-l10n/Makefile 1.12 - www/firefox140-l10n/distinfo 1.12 - www/firefox140/Makefile 1.17 - www/firefox140/distinfo 1.17 - www/firefox140/patches/patch-media_ffvpx_libavcodec_parser__list.c deleted --- Module Name: pkgsrc Committed By: gutteridge Date: Thu May 21 15:34:06 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Removed Files: pkgsrc/www/firefox140/patches: patch-media_ffvpx_libavcodec_parser__list.c Log Message: firefox140: update to 140.11 Mozilla Foundation Security Advisory 2026-48 Security Vulnerabilities fixed in Firefox ESR 140.11 Announced May 19, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.11 #CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component Reporter zx Impact high References Bug 2029070 #CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component Reporter ggwhyp Impact high References Bug 2036978 #CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component Reporter Satoki Tsuji Impact high References Bug 2038439 #CVE-2026-8391: Other issue in the JavaScript Engine component Reporter ggwhyp Impact high References Bug 2038575 #CVE-2026-8401: Sandbox escape in the Profile Backup component Reporter ggwhyp Impact high References Bug 2038679 #CVE-2026-8949: Integer overflow in the Widget: Win32 component Reporter q1 Impact moderate References Bug 1355639 #CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component Reporter Jakub Szymsza Impact moderate References Bug 1965430 #CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component Reporter stevej Impact moderate References Bug 2029511 #CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component Reporter Ameen Basha M K Impact moderate References Bug 2030747 #CVE-2026-8955: Privilege escalation in the DOM: Workers component Reporter lebr0nli Impact moderate References Bug 2031064 #CVE-2026-8956: Integer overflow in the Networking: JAR component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2032427 #CVE-2026-8957: Privilege escalation in the Enterprise Policies component Reporter Mateusz Dobrzyński Impact moderate References Bug 2033850 #CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component Reporter Yaqoub Aldurayhim Impact moderate References Bug 2034713 #CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component Reporter Ameen Basha M K Impact moderate References Bug 2034754 #CVE-2026-8961: Spoofing issue in the Form Autofill component Reporter Hafiizh Impact low References Bug 1962625 #CVE-2026-8962: Mitigation bypass in the DOM: Security component Reporter Manojkumar Jaganathan Impact low References Bug 2004804 #CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component Reporter Tristan Madani Impact low References Bug 2030467 #CVE-2026-8970: Privilege escalation in the Security component Reporter pakhunov.anton.n Impact low References Bug 2032174 #CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 Reporter Nika Layzell, Randell Jesup, Timothy Nikkel, Tom Schuster and the Mozilla Fuzzing Team Impact moderate Description Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 #CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 Reporter Andrew McCreight, Valentin Gosu, Nika Layzell, Tom Schuster and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 --- Module Name: pkgsrc Committed By: gutteridge Date: Thu May 21 15:35:54 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.11 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.11.2.5 2026/05/08 11:16:50 maya Exp $ d3 3 a5 3 BLAKE2s (firefox-140.11.0esr.source.tar.xz) = 567b3ce95be1e3809dbd1d4e36a9b4fed544bd4b8e3bf24fff238daf0743bfaf SHA512 (firefox-140.11.0esr.source.tar.xz) = d06adb3ef4de1324e3d61872d70de31ab08ac013f33903549bed28c6ebcc5b4dee94bb36388282c1935d77d1a564079f3adbf08d6bb80284a899cbb3d861300c Size (firefox-140.11.0esr.source.tar.xz) = 637083992 bytes d29 1 @ 1.10 log @firefox140: update to 140.8 Mozilla Foundation Security Advisory 2026-15 Security Vulnerabilities fixed in Firefox ESR 140.8 Announced February 24, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.8 #CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component Reporter Igor Morgenstern Impact high References Bug 2001637 #CVE-2026-2758: Use-after-free in the JavaScript: GC component Reporter Gary Kwong Impact high References Bug 2009608 #CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component Reporter stevej Impact high References Bug 2010933 #CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component Reporter Oskar L Impact high References Bug 2011062 #CVE-2026-2761: Sandbox escape in the Graphics: WebRender component Reporter Oskar L Impact high References Bug 2011063 #CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component Reporter André Bargull Impact high References Bug 2011649 #CVE-2026-2763: Use-after-free in the JavaScript Engine component Reporter Information to follow Impact high References Bug 2012018 #CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component Reporter Information to follow Impact high References Bug 2012608 #CVE-2026-2765: Use-after-free in the JavaScript Engine component Reporter Information to follow Impact high References Bug 2013562 #CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component Reporter Information to follow Impact high References Bug 2013583 #CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component Reporter Sajeeb Lohani Impact high References Bug 2013741 #CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component Reporter Sajeeb Lohani Impact high References Bug 2014101 #CVE-2026-2769: Use-after-free in the Storage: IndexedDB component Reporter Information to follow Impact high References Bug 2014550 #CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component Reporter Information to follow Impact high References Bug 2014585 #CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component Reporter Information to follow Impact high References Bug 2014593 #CVE-2026-2772: Use-after-free in the Audio/Video: Playback component Reporter Information to follow Impact high References Bug 2014827 #CVE-2026-2773: Incorrect boundary conditions in the Web Audio component Reporter Information to follow Impact high References Bug 2014832 #CVE-2026-2774: Integer overflow in the Audio/Video component Reporter Information to follow Impact high References Bug 2014883 #CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component Reporter Information to follow Impact high References Bug 2015199 #CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software Reporter Sajeeb Lohani Impact high References Bug 2015266 #CVE-2026-2777: Privilege escalation in the Messaging System component Reporter Richard Belisle Impact high References Bug 2015305 #CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component Reporter Sajeeb Lohani Impact high References Bug 2016358 #CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component Reporter Alex Mayorga Impact moderate References Bug 1164141 #CVE-2026-2780: Privilege escalation in the Netmonitor component Reporter RyotaK Impact moderate References Bug 2007829 #CVE-2026-2781: Integer overflow in the Libraries component in NSS Reporter Clay Ver Valen Impact moderate References Bug 2009552 #CVE-2026-2782: Privilege escalation in the Netmonitor component Reporter Cody Impact moderate References Bug 2010743 #CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component Reporter x0e Impact moderate References Bug 2010943 #CVE-2026-2784: Mitigation bypass in the DOM: Security component Reporter D. Santos Impact moderate References Bug 2012984 #CVE-2026-2785: Invalid pointer in the JavaScript Engine component Reporter Information to follow Impact moderate References Bug 2013549 #CVE-2026-2786: Use-after-free in the JavaScript Engine component Reporter Information to follow Impact moderate References Bug 2013612 #CVE-2026-2787: Use-after-free in the DOM: Window and Location component Reporter Information to follow Impact moderate References Bug 2014560 #CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component Reporter Information to follow Impact moderate References Bug 2014824 #CVE-2026-2789: Use-after-free in the Graphics: ImageLib component Reporter Information to follow Impact moderate References Bug 2015179 #CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component Reporter Surya Dev Singh Impact low References Bug 2008426 #CVE-2026-2791: Mitigation bypass in the Networking: Cache component Reporter Information to follow Impact low References Bug 2015220 #CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 Reporter Andrew McCreight, Maurice Dauer, Olli Pettay, Ryan Hunt Impact high Description Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 #CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 Reporter Andrew McCreight, Christian Holler Impact high Description Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.9 2026/02/17 00:26:49 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.8.0esr.source.tar.xz) = ddbe76491a3a5af88432b96b26a2ebb656819a780f2249d5198b4a8b94ac41ad SHA512 (firefox-140.8.0esr.source.tar.xz) = 3baca73c5c264884afa4b1d76ded4417119640e1161b8fed4ca406f0ec44e7f685258f5085f473dc9eff9057a6548a9b59cec3c696358dd1032503aa75f91d05 Size (firefox-140.8.0esr.source.tar.xz) = 633564864 bytes @ 1.9 log @firefox140: update to 140.7.1 Addresses a single high-severity security issue: CVE-2026-2447: Heap buffer overflow in libvpx @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.8 2026/01/13 17:20:06 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.7.1esr.source.tar.xz) = d916a5d95215d3efba9cb45f083396a4a57b41c92ef5d5f85e4a7687ffaccc23 SHA512 (firefox-140.7.1esr.source.tar.xz) = 7d867fa3c9c94903f6583be75ad4aa8d918f98f74c99c6615a0e40caf21c545a30149115214876693ef1758a320ebdccef017c484365c195e55998cce088663c Size (firefox-140.7.1esr.source.tar.xz) = 635535480 bytes @ 1.8 log @firefox140: update to 140.7.0 Mozilla Foundation Security Advisory 2026-03 Security Vulnerabilities fixed in Firefox ESR 140.7 Announced January 13, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.7 #CVE-2026-0877: Mitigation bypass in the DOM: Security component Reporter mingijung Impact high References Bug 1999257 #CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Oskar L Impact high References Bug 2003989 #CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the Graphics component Reporter Oskar L Impact high References Bug 2004602 #CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics component Reporter Oskar L Impact high References Bug 2005014 #CVE-2026-0882: Use-after-free in the IPC component Reporter Randell Jesup Impact high References Bug 1924125 #CVE-2025-14327: Spoofing issue in the Downloads Panel component Reporter Caro Kann Impact moderate References Bug 1970743 #CVE-2026-0883: Information disclosure in the Networking component Reporter Vladislav Plyatsok Impact moderate References Bug 1989340 #CVE-2026-0884: Use-after-free in the JavaScript Engine component Reporter Gary Kwong and Nan Wang Impact moderate References Bug 2003588 #CVE-2026-0885: Use-after-free in the JavaScript: GC component Reporter Irvan Kurniawan Impact moderate References Bug 2003607 #CVE-2026-0886: Incorrect boundary conditions in the Graphics component Reporter Oskar L Impact moderate References Bug 2005658 #CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer component Reporter Lyra Rebane Impact moderate References Bug 2006500 #CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop component Reporter Edgar Chen Impact low References Bug 2005081 #CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 Reporter Andrew McCreight, Dennis Jackson and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.7 2026/01/06 23:27:50 gutteridge Exp $ d3 3 a5 3 BLAKE2s (firefox-140.7.0esr.source.tar.xz) = aff38f46c7b263dd45a2362eb269f25a7db3b6218e0480c88dcdad66100ab3f7 SHA512 (firefox-140.7.0esr.source.tar.xz) = 7781b1e203130c1cdf2a0c2ecb05a9cfa824c75d467e7faca78b66bd5568c821324112aecb774883d9f447af7fa4ade36488ff1017255af5510c8f641990e472 Size (firefox-140.7.0esr.source.tar.xz) = 641146512 bytes @ 1.7 log @firefox140: fix builds with ICU >= 78.1 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.6 2026/01/02 14:27:02 tnn Exp $ d3 3 a5 3 BLAKE2s (firefox-140.6.0esr.source.tar.xz) = 7a8bd60f08fdd421ac94fa13ff776eff21cba8f432d85a60fce3a2c0c57066d6 SHA512 (firefox-140.6.0esr.source.tar.xz) = ed66657bd4b2d94791892261d7c0c0d950b4f630d12ab28a777d93393427451a9aa125e5a01ee15f2ac0ff378d0be074a08583dcffd35609112ba4e6f9ada798 Size (firefox-140.6.0esr.source.tar.xz) = 643086844 bytes @ 1.6 log @firefox140: backport patch @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.5 2025/12/24 02:11:49 gutteridge Exp $ d20 1 @ 1.5 log @firefox140: fix builds with Python >= 3.14 Build failure reported by Hisashi Todd Fujinaka in PR pkg/59854. A fix was applied upstream by Mozilla directly against their "vendored" version of jsonschema, but not backported to the ESR branch. @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.4 2025/12/15 21:04:49 gutteridge Exp $ d28 1 a28 1 SHA1 (patch-media_ffvpx_libavutil_arm_bswap.h) = 019677e249e744baea857ca17ef69d977f43b3a4 @ 1.4 log @firefox140: fix builds with NetBSD >= 11.99.4 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.3 2025/12/11 11:05:21 leot Exp $ d49 1 @ 1.4.2.1 log @Pullup ticket #7038 - requested by gutteridge www/firefox140: build fix Revisions pulled up: - www/firefox140/distinfo 1.5 - www/firefox140/patches/patch-third__party_python_jsonschema_jsonschema_validators.py 1.1 --- Module Name: pkgsrc Committed By: gutteridge Date: Wed Dec 24 02:11:49 UTC 2025 Modified Files: pkgsrc/www/firefox140: distinfo Added Files: pkgsrc/www/firefox140/patches: patch-third__party_python_jsonschema_jsonschema_validators.py Log Message: firefox140: fix builds with Python >= 3.14 Build failure reported by Hisashi Todd Fujinaka in PR pkg/59854. A fix was applied upstream by Mozilla directly against their "vendored" version of jsonschema, but not backported to the ESR branch. @ text @d1 1 a1 1 $NetBSD$ a48 1 SHA1 (patch-third__party_python_jsonschema_jsonschema_validators.py) = 24c84c8f8ca2bc39088001dffdcb05be3ac84c76 @ 1.4.2.2 log @Pullup ticket #7044 - requested by gutteridge www/firefox140: Security fix www/firefox140-l10n: Security fix Revisions pulled up: - www/firefox140-l10n/Makefile 1.4 - www/firefox140-l10n/distinfo 1.4 - www/firefox140/Makefile 1.8 - www/firefox140/distinfo 1.8 --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Jan 13 17:20:06 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Log Message: firefox140: update to 140.7.0 Mozilla Foundation Security Advisory 2026-03 Security Vulnerabilities fixed in Firefox ESR 140.7 Announced January 13, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.7 #CVE-2026-0877: Mitigation bypass in the DOM: Security component Reporter mingijung Impact high References Bug 1999257 #CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component Reporter Oskar L Impact high References Bug 2003989 #CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the Graphics component Reporter Oskar L Impact high References Bug 2004602 #CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics component Reporter Oskar L Impact high References Bug 2005014 #CVE-2026-0882: Use-after-free in the IPC component Reporter Randell Jesup Impact high References Bug 1924125 #CVE-2025-14327: Spoofing issue in the Downloads Panel component Reporter Caro Kann Impact moderate References Bug 1970743 #CVE-2026-0883: Information disclosure in the Networking component Reporter Vladislav Plyatsok Impact moderate References Bug 1989340 #CVE-2026-0884: Use-after-free in the JavaScript Engine component Reporter Gary Kwong and Nan Wang Impact moderate References Bug 2003588 #CVE-2026-0885: Use-after-free in the JavaScript: GC component Reporter Irvan Kurniawan Impact moderate References Bug 2003607 #CVE-2026-0886: Incorrect boundary conditions in the Graphics component Reporter Oskar L Impact moderate References Bug 2005658 #CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer component Reporter Lyra Rebane Impact moderate References Bug 2006500 #CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop component Reporter Edgar Chen Impact low References Bug 2005081 #CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 Reporter Andrew McCreight, Dennis Jackson and the Mozilla Fuzzing Team Impact high Description Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Jan 13 17:23:35 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.7.0 Sync with www/firefox140 version. @ text @d3 3 a5 3 BLAKE2s (firefox-140.7.0esr.source.tar.xz) = aff38f46c7b263dd45a2362eb269f25a7db3b6218e0480c88dcdad66100ab3f7 SHA512 (firefox-140.7.0esr.source.tar.xz) = 7781b1e203130c1cdf2a0c2ecb05a9cfa824c75d467e7faca78b66bd5568c821324112aecb774883d9f447af7fa4ade36488ff1017255af5510c8f641990e472 Size (firefox-140.7.0esr.source.tar.xz) = 641146512 bytes @ 1.4.2.3 log @Pullup ticket #7045 - requested by gutteridge www/firefox140: security fix www/firefox140-l10n: dependent update Revisions pulled up: - www/firefox140-l10n/Makefile 1.6 - www/firefox140-l10n/distinfo 1.6 - www/firefox140/Makefile 1.11 - www/firefox140/distinfo 1.10 --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Feb 24 14:07:55 UTC 2026 Modified Files: pkgsrc/www/firefox140: Makefile distinfo Log Message: firefox140: update to 140.8 Mozilla Foundation Security Advisory 2026-15 Security Vulnerabilities fixed in Firefox ESR 140.8 Announced February 24, 2026 Impact high Products Firefox ESR Fixed in Firefox ESR 140.8 #CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component Reporter Igor Morgenstern Impact high References Bug 2001637 #CVE-2026-2758: Use-after-free in the JavaScript: GC component Reporter Gary Kwong Impact high References Bug 2009608 #CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component Reporter stevej Impact high References Bug 2010933 #CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component Reporter Oskar L Impact high References Bug 2011062 #CVE-2026-2761: Sandbox escape in the Graphics: WebRender component Reporter Oskar L Impact high References Bug 2011063 #CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component Reporter André Bargull Impact high References Bug 2011649 #CVE-2026-2763: Use-after-free in the JavaScript Engine component Reporter Information to follow Impact high References Bug 2012018 #CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component Reporter Information to follow Impact high References Bug 2012608 #CVE-2026-2765: Use-after-free in the JavaScript Engine component Reporter Information to follow Impact high References Bug 2013562 #CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component Reporter Information to follow Impact high References Bug 2013583 #CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component Reporter Sajeeb Lohani Impact high References Bug 2013741 #CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component Reporter Sajeeb Lohani Impact high References Bug 2014101 #CVE-2026-2769: Use-after-free in the Storage: IndexedDB component Reporter Information to follow Impact high References Bug 2014550 #CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component Reporter Information to follow Impact high References Bug 2014585 #CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component Reporter Information to follow Impact high References Bug 2014593 #CVE-2026-2772: Use-after-free in the Audio/Video: Playback component Reporter Information to follow Impact high References Bug 2014827 #CVE-2026-2773: Incorrect boundary conditions in the Web Audio component Reporter Information to follow Impact high References Bug 2014832 #CVE-2026-2774: Integer overflow in the Audio/Video component Reporter Information to follow Impact high References Bug 2014883 #CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component Reporter Information to follow Impact high References Bug 2015199 #CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software Reporter Sajeeb Lohani Impact high References Bug 2015266 #CVE-2026-2777: Privilege escalation in the Messaging System component Reporter Richard Belisle Impact high References Bug 2015305 #CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component Reporter Sajeeb Lohani Impact high References Bug 2016358 #CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component Reporter Alex Mayorga Impact moderate References Bug 1164141 #CVE-2026-2780: Privilege escalation in the Netmonitor component Reporter RyotaK Impact moderate References Bug 2007829 #CVE-2026-2781: Integer overflow in the Libraries component in NSS Reporter Clay Ver Valen Impact moderate References Bug 2009552 #CVE-2026-2782: Privilege escalation in the Netmonitor component Reporter Cody Impact moderate References Bug 2010743 #CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component Reporter x0e Impact moderate References Bug 2010943 #CVE-2026-2784: Mitigation bypass in the DOM: Security component Reporter D. Santos Impact moderate References Bug 2012984 #CVE-2026-2785: Invalid pointer in the JavaScript Engine component Reporter Information to follow Impact moderate References Bug 2013549 #CVE-2026-2786: Use-after-free in the JavaScript Engine component Reporter Information to follow Impact moderate References Bug 2013612 #CVE-2026-2787: Use-after-free in the DOM: Window and Location component Reporter Information to follow Impact moderate References Bug 2014560 #CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component Reporter Information to follow Impact moderate References Bug 2014824 #CVE-2026-2789: Use-after-free in the Graphics: ImageLib component Reporter Information to follow Impact moderate References Bug 2015179 #CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component Reporter Surya Dev Singh Impact low References Bug 2008426 #CVE-2026-2791: Mitigation bypass in the Networking: Cache component Reporter Information to follow Impact low References Bug 2015220 #CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 Reporter Andrew McCreight, Maurice Dauer, Olli Pettay, Ryan Hunt Impact high Description Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 #CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 Reporter Andrew McCreight, Christian Holler Impact high Description Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Feb 24 14:09:03 UTC 2026 Modified Files: pkgsrc/www/firefox140-l10n: Makefile distinfo Log Message: firefox140-l10n: update to 140.8.0 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.4.2.2 2026/01/14 18:58:46 maya Exp $ d3 3 a5 3 BLAKE2s (firefox-140.8.0esr.source.tar.xz) = ddbe76491a3a5af88432b96b26a2ebb656819a780f2249d5198b4a8b94ac41ad SHA512 (firefox-140.8.0esr.source.tar.xz) = 3baca73c5c264884afa4b1d76ded4417119640e1161b8fed4ca406f0ec44e7f685258f5085f473dc9eff9057a6548a9b59cec3c696358dd1032503aa75f91d05 Size (firefox-140.8.0esr.source.tar.xz) = 633564864 bytes @ 1.3 log @firefox140{,-l10n}: Update to 140.6.0 Changes: 140.6.0 - Security fixes (MFSA2025-94) Discussed with PMC and ok by during carefulperiod 2, thanks! @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.2 2025/11/12 19:48:10 leot Exp $ d35 1 a35 1 SHA1 (patch-third__party_abseil-cpp_absl_debugging_internal_elf__mem__image.cc) = 2b5955027add79d1b8709667b0433b2d19fbd1bc @ 1.2 log @firefox140: Update to 140.5.0 ESR Changes: Various security fixes (MFSA2025-88). @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.1 2025/10/19 11:56:55 leot Exp $ d3 3 a5 3 BLAKE2s (firefox-140.5.0esr.source.tar.xz) = a88714ad96cbf5af2f8f1b8b33361acfde85b023761354244b18e35c6439d02a SHA512 (firefox-140.5.0esr.source.tar.xz) = 412236a25cbea171bd5bd535e45c3ba40957a94e1f8dd3ab74241e0aa1c4075fcb8d394b9619599d60ce3e4563e712c825fa8bec441794f229356802f72b2861 Size (firefox-140.5.0esr.source.tar.xz) = 636823136 bytes @ 1.1 log @firefox140: Import firefox140-140.4.0 as www/firefox140 Mozilla Firefox is a free, open-source and cross-platform web browser for Windows, Linux, MacOS X and many other operating systems. It is fast and easy to use, and offers many advantages over other web browsers, such as tabbed browsing and the ability to block pop-up windows. Firefox also offers excellent bookmark and history management, and it can be extended by developers using industry standards such as XML, CSS, JavaScript, C++, etc. Many extensions are available. Note: Due to upstream's trademark policies, this package identifies as "Nightly" rather than "Firefox" by default. This package provides Firefox 140 Extended Support Release. Based on latest 140.x www/firefox and adjusted for ESR. Thanks to for help! @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.559 2025/07/23 13:57:35 ryoon Exp $ d3 3 a5 3 BLAKE2s (firefox-140.4.0esr.source.tar.xz) = 13e7d026640f50b94584792be30953a2e5c59214ae89b0207b276065fdb5407a SHA512 (firefox-140.4.0esr.source.tar.xz) = cfce0bdcf6d4599c7b96bccd9fd1390bfb3645db9276a369a30760ce6819850aaa4251869e6bd3c5d8582ea3728b920762c5f16f7ce12ce151c3e74327b8c811 Size (firefox-140.4.0esr.source.tar.xz) = 639276460 bytes @