SB2026082006 - Debian update for firefox-esr



SB2026082006 - Debian update for firefox-esr

Published: August 20, 2026

Security Bulletin ID SB2026082006
CSH Severity
High
Patch available
YES
Number of vulnerabilities 31
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 42% Medium 48% Low 10%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 31 vulnerabilities.


1) Protection mechanism failure (CVE-ID: CVE-2026-74959)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper protection mechanism implementation in the Storage: Cache API component when handling cached web content. A remote attacker can trigger specially crafted web content to bypass a security mitigation.

User interaction is required to visit a specially crafted website or URL.


2) Buffer overflow (CVE-ID: CVE-2026-74990)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when rendering content or handling browser operations. A remote attacker can trigger crafted browser interactions to execute arbitrary code.

Multiple internally found bugs are covered by this entry, and the advisory notes that some showed evidence of memory corruption or another security-relevant defect.


3) Buffer overflow (CVE-ID: CVE-2026-74987)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.

The advisory states that some of the internally found bugs showed evidence of memory corruption or another security-relevant defect.


4) Protection mechanism failure (CVE-ID: CVE-2026-74983)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper protection mechanism implementation in the Data Loss Prevention component when processing web content. A remote attacker can trigger specially crafted web content to bypass a security mitigation.

User interaction is required to visit a specially crafted website or URL.


5) Incorrect calculation (CVE-ID: CVE-2026-74976)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing crafted script content. A remote attacker can cause the browser to execute specially crafted script content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


6) Improper access control (CVE-ID: CVE-2026-74974)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass the same-origin policy.

The vulnerability exists due to improper access control in the Graphics: ImageLib component when rendering content. A remote attacker can cause the browser to process crafted content to bypass the same-origin policy.


7) Use-after-free (CVE-ID: CVE-2026-74973)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a race condition leading to use-after-free in the Graphics component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.


8) Information disclosure (CVE-ID: CVE-2026-74972)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the DOM: Push Subscriptions component when handling push subscription data. A remote attacker can trigger specially crafted web content to disclose sensitive information.

User interaction is required to visit a specially crafted website or URL.


9) Information disclosure (CVE-ID: CVE-2026-74971)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the DOM: UI Events & Focus Handling component when processing web content. A remote attacker can trigger specially crafted web content to disclose sensitive information.


10) Use-after-free (CVE-ID: CVE-2026-74969)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Layout: Text and Fonts component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.


11) Origin validation error (CVE-ID: CVE-2026-74967)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass the same-origin policy.

The vulnerability exists due to improper access control in the Audio/Video: Playback component when processing media content. A remote attacker can cause the browser to handle specially crafted media content to bypass the same-origin policy.

User interaction is required to visit a specially crafted website or URL.


12) Improper privilege management (CVE-ID: CVE-2026-74965)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Shell Integration component when processing crafted content. A remote attacker can trigger specially crafted content to escalate privileges.

User interaction is required to visit a specially crafted website or URL.


13) Integer overflow (CVE-ID: CVE-2026-74964)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Graphics component when rendering crafted web content. A remote attacker can cause the browser to process specially crafted web content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


14) Origin validation error (CVE-ID: CVE-2026-74963)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass the same-origin policy.

The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to bypass the same-origin policy.

User interaction is required to visit a specially crafted website or URL.


15) Origin validation error (CVE-ID: CVE-2026-74962)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass site isolation.

The vulnerability exists due to improper isolation enforcement in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to bypass site isolation.

User interaction is required to visit a specially crafted website or URL.


16) Origin validation error (CVE-ID: CVE-2026-74960)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass site isolation.

The vulnerability exists due to improper isolation enforcement in the WebExtensions component when handling extension-related web content. A remote attacker can cause the browser to process specially crafted web content to bypass site isolation.

User interaction is required to visit a specially crafted website or URL.


17) Improper access control (CVE-ID: CVE-2026-74934)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass site isolation.

The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to bypass site isolation.


18) Protection mechanism failure (CVE-ID: CVE-2026-74957)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper protection mechanism implementation in the Safe Browsing component when processing web content. A remote attacker can cause the browser to handle specially crafted web content to bypass a security mitigation.

User interaction is required to visit a specially crafted website or URL.


19) Improper privilege management (CVE-ID: CVE-2026-74953)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to escalate privileges.

User interaction is required to visit a specially crafted website or URL.


20) Use-after-free (CVE-ID: CVE-2026-74949)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when rendering web content. A remote attacker can cause the browser to process specially crafted web content to escalate privileges.

User interaction is required to visit a specially crafted website or URL.


21) Information disclosure (CVE-ID: CVE-2026-74948)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the Graphics component when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.


22) Buffer overflow (CVE-ID: CVE-2026-74946)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to escalate privileges.


23) Information disclosure (CVE-ID: CVE-2026-74945)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the Graphics: Text component when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.


24) Use-after-free (CVE-ID: CVE-2026-74944)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


25) Use-after-free (CVE-ID: CVE-2026-74943)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Graphics: ImageLib component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.


26) Improper access control (CVE-ID: CVE-2026-74942)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Remote Settings Client component when processing remote settings data. A remote attacker can trigger crafted browser interactions to escalate privileges.


27) Improper privilege management (CVE-ID: CVE-2026-74941)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process specially crafted web content to escalate privileges.

User interaction is required to visit a specially crafted website or URL.


28) Use-after-free (CVE-ID: CVE-2026-74940)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Graphics: Text component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.


29) Improper access control (CVE-ID: CVE-2026-74939)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted browser interactions to escalate privileges.


30) Use-after-free (CVE-ID: CVE-2026-74936)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


31) Improper access control (CVE-ID: CVE-2026-74935)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Networking component when handling web content. A remote attacker can trigger crafted browser interactions to escalate privileges.


Remediation

Install update from vendor's website.