SB2026091362 - openEuler 24.03 LTS SP1 update for firefox



SB2026091362 - openEuler 24.03 LTS SP1 update for firefox

Published: September 13, 2026

Security Bulletin ID SB2026091362
CSH Severity
High
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Improper privilege management (CVE-ID: CVE-2026-16365)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Workers component when handling worker operations. A remote attacker can trigger crafted worker behavior to escalate privileges.


2) Improper access control (CVE-ID: CVE-2026-75874)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper isolation in the Remote Settings Client component when handling remote settings data. A remote attacker can trigger the vulnerable component to escape the sandbox.


3) Use-after-free (CVE-ID: CVE-2026-84119)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in DOM: Navigation component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.

User interaction is required.


4) Use-after-free (CVE-ID: CVE-2026-84120)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in Audio/Video component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to execute arbitrary code.

User interaction is required.


5) Use-after-free (CVE-ID: CVE-2026-84121)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in DOM: Security component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.

User interaction is required.


6) Use-after-free (CVE-ID: CVE-2026-84122)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Audio/Video component when processing crafted media content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


7) Use-after-free (CVE-ID: CVE-2026-84124)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


8) NULL pointer dereference (CVE-ID: CVE-2026-84131)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to invalid pointer dereference in Graphics component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escalate privileges.

User interaction is required.


9) Buffer overflow (CVE-ID: CVE-2026-84143)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger a security-relevant defect to execute arbitrary code.

The advisory describes multiple internally found bugs, some of which showed evidence of memory corruption or another security-relevant defect.


10) Buffer overflow (CVE-ID: CVE-2026-84145)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing web content. A remote attacker can convince the victim to visit a specially crafted website to cause a denial of service or execute arbitrary code.

The issue covers multiple internally found bugs.


Remediation

Install update from vendor's website.