SB20260917225 - Debian update for firefox-esr
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 28 vulnerabilities.
1) Protection mechanism failure (CVE-ID: CVE-2026-92019)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to insufficient mitigation enforcement in the Remote Settings Client component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to bypass a security mitigation.
User interaction is required to visit the crafted website.
2) NULL pointer dereference (CVE-ID: CVE-2026-92032)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to an invalid pointer in the Graphics component when processing web content. A remote attacker can trigger the invalid pointer condition to escape the sandbox.
3) Information disclosure (CVE-ID: CVE-2026-92031)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to information disclosure in the Graphics: ImageLib component when processing web content. A remote attacker can process web content with the affected component to disclose sensitive information.
4) Protection mechanism failure (CVE-ID: CVE-2026-92030)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a mitigation.
The vulnerability exists due to a protection mechanism failure in the DOM: Copy & Paste and Drag & Drop component when processing web content. A remote attacker can exploit the protection mechanism failure to bypass a mitigation.
5) Use-after-free (CVE-ID: CVE-2026-92029)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the SVG component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
6) Use-after-free (CVE-ID: CVE-2026-92028)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
7) Use-after-free (CVE-ID: CVE-2026-92027)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: Streams component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
8) Use-after-free (CVE-ID: CVE-2026-92026)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Networking component when processing web content. A remote attacker can trigger the use-after-free condition to execute arbitrary code.
9) Use-after-free (CVE-ID: CVE-2026-92025)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: Navigation component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
10) Use-after-free (CVE-ID: CVE-2026-92024)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the SVG component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
11) Use-after-free (CVE-ID: CVE-2026-92023)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the XML component when parsing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
12) Use-after-free (CVE-ID: CVE-2026-92022)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: HTML Parser component when parsing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
13) Use-after-free (CVE-ID: CVE-2026-92021)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript Engine: JIT component when processing web content. A remote attacker can trigger the use-after-free condition to execute arbitrary code.
14) Input validation error (CVE-ID: CVE-2026-92020)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: WebRender component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
15) Use-after-free (CVE-ID: CVE-2026-92005)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Audio/Video: Web Codecs component when processing web content. A remote attacker can trigger the use-after-free condition to execute arbitrary code.
16) Protection mechanism failure (CVE-ID: CVE-2026-92018)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to improper sandbox isolation in the DOM: Core & HTML component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to escape the browser sandbox.
User interaction is required to visit the crafted website.
17) Improper privilege management (CVE-ID: CVE-2026-92017)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the DOM: Service Workers component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
18) Use-after-free (CVE-ID: CVE-2026-92016)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Disability Access APIs component when processing web content. A remote attacker can trigger the use-after-free condition to execute arbitrary code.
19) Improper privilege management (CVE-ID: CVE-2026-92015)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the WebExtensions component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
20) Input validation error (CVE-ID: CVE-2026-92014)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
21) Input validation error (CVE-ID: CVE-2026-92013)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
22) Input validation error (CVE-ID: CVE-2026-92012)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
23) Input validation error (CVE-ID: CVE-2026-92011)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
24) Input validation error (CVE-ID: CVE-2026-92010)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
25) Input validation error (CVE-ID: CVE-2026-92009)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
26) Input validation error (CVE-ID: CVE-2026-92008)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
27) Input validation error (CVE-ID: CVE-2026-92007)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
28) Input validation error (CVE-ID: CVE-2026-92006)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
Remediation
Install update from vendor's website.