SB2026090308 - Debian update for firefox-esr



SB2026090308 - Debian update for firefox-esr

Published: September 3, 2026

Security Bulletin ID SB2026090308
CSH Severity
High
Patch available
YES
Number of vulnerabilities 11
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 11 vulnerabilities.


1) Improper privilege management (CVE-ID: CVE-2026-16365)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Workers component when handling worker operations. A remote attacker can trigger crafted worker behavior to escalate privileges.


2) Improper privilege management (CVE-ID: CVE-2026-16371)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to escalate privileges.


3) Improper access control (CVE-ID: CVE-2026-75874)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper isolation in the Remote Settings Client component when handling remote settings data. A remote attacker can trigger the vulnerable component to escape the sandbox.


4) Use-after-free (CVE-ID: CVE-2026-84119)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in DOM: Navigation component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.

User interaction is required.


5) Use-after-free (CVE-ID: CVE-2026-84120)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in Audio/Video component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to execute arbitrary code.

User interaction is required.


6) Use-after-free (CVE-ID: CVE-2026-84121)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in DOM: Security component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.

User interaction is required.


7) Use-after-free (CVE-ID: CVE-2026-84122)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Audio/Video component when processing crafted media content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


8) Use-after-free (CVE-ID: CVE-2026-84124)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


9) NULL pointer dereference (CVE-ID: CVE-2026-84131)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to invalid pointer dereference in Graphics component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escalate privileges.

User interaction is required.


10) Buffer overflow (CVE-ID: CVE-2026-84143)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger a security-relevant defect to execute arbitrary code.

The advisory describes multiple internally found bugs, some of which showed evidence of memory corruption or another security-relevant defect.


11) Buffer overflow (CVE-ID: CVE-2026-84145)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing web content. A remote attacker can convince the victim to visit a specially crafted website to cause a denial of service or execute arbitrary code.

The issue covers multiple internally found bugs.


Remediation

Install update from vendor's website.