Commit Graph
131 Commits
Author SHA1 Message Date
Ian Eure e9c29f8733 gnu: librewolf: Update to 153.0.3-1.
* gnu/packages/librewolf.scm (librewolf): Update to 153.0.3-1.
(firefox-l10n): Update to 6795ea14a5bd5ed79a930e6759823c7236476ae4.
(make-librewolf-source): Make ff_source_tarball substitution tolerant of
whitespace, and preserve what whitespace is present.

Change-Id: Ifaba8b5bbaba829ad62b8c7507fa877dc3bd78b4
2026-08-07 21:17:25 -07:00
moksh 7dcafc4d35 gnu: librewolf: Update to 153.0-3. [security-fixes]
* gnu/packages/librewolf.scm (librewolf): Update to 153.0-2.

Firefox 153.0 contains fixes for:
CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation
                component
CVE-2026-16350: Incorrect boundary conditions in the Audio/Video:
                cubeb component
CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
CVE-2026-16351: Sandbox escape due to use-after-free in the DOM:
                Navigation component
CVE-2026-16352: Sandbox escape due to use-after-free in the Disability
                Access APIs component
CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly
                component
CVE-2026-16364: Incorrect boundary conditions in the Audio/Video:
                Playback component
CVE-2026-16365: Privilege escalation in the DOM: Workers component
CVE-2026-16366: Privilege escalation in the DOM: Navigation component
CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL)
                component
CVE-2026-16354: Information disclosure in the Graphics: ImageLib
                component
CVE-2026-16367: Sandbox escape due to invalid pointer in the
                Disability Access APIs component
CVE-2026-16368: Incorrect boundary conditions in the JavaScript:
                WebAssembly component
CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly
                component
CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT
                component
CVE-2026-16356: Sandbox escape due to use-after-free in the Disability
                Access APIs component
CVE-2026-16357: Incorrect boundary conditions in the Graphics
                component
CVE-2026-16370: Mitigation bypass in the DOM: Networking component
CVE-2026-16371: Privilege escalation in the DOM: Navigation component
CVE-2026-16372: Privilege escalation in the DOM: Content Processes
                component
CVE-2026-16373: Information disclosure in the Privacy component in
                Firefox for Android
CVE-2026-16374: Information disclosure in the Framework component in
                DevTools
CVE-2026-16375: Site isolation issue in the Networking: HTTP component
CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
CVE-2026-16377: Mitigation bypass in the PDF Viewer component
CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop
                component
CVE-2026-16379: Privilege escalation in the DOM: Content Processes
                component
CVE-2026-16358: Site isolation issue in the Graphics: WebRender
                component
CVE-2026-16380: Mitigation bypass in the Networking component
CVE-2026-16381: Same-origin policy bypass in the Networking: DNS
                component
CVE-2026-16382: Mitigation bypass in the DOM: Service Workers
                component
CVE-2026-16383: Mitigation bypass in the DOM: Networking component
CVE-2026-16384: Information disclosure due to uninitialized memory in
                the Graphics: WebGPU component
CVE-2026-16385: Information disclosure due to uninitialized memory in
                the Graphics: WebGPU component
CVE-2026-16386: Information disclosure due to uninitialized memory in
                the Graphics: WebGPU component
CVE-2026-16387: Site isolation issue in the Networking component
CVE-2026-16388: Sandbox escape in the DOM: Networking component
CVE-2026-16389: Incorrect boundary conditions, integer overflow in the
                Libraries component in NSS
CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
CVE-2026-16391: Information disclosure in the Storage: IndexedDB
                component
CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT
                component
CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU
                component
CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
                component
CVE-2026-16394: Mitigation bypass in the DOM: Security component
CVE-2026-16395: Integer overflow in the Audio/Video component
CVE-2026-16396: Privilege escalation in WebExtensions
CVE-2026-16397: Clickjacking issue in the WebExtensions component in
                Firefox for Android
CVE-2026-16398: Site isolation issue in the Graphics component
CVE-2026-16399: Site isolation issue in the DOM: Navigation component
CVE-2026-16400: Information disclosure in the DOM: Security component
CVE-2026-16401: Privilege escalation in the Data Loss Prevention
                component
CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
CVE-2026-16403: Spoofing issue in the Address Bar component
CVE-2026-16404: Spoofing issue in Firefox for Android
CVE-2026-16405: Information disclosure in the Networking: WebSockets
                component
CVE-2026-16406: Mitigation bypass in the Networking component
CVE-2026-16407: Mitigation bypass in the DOM: Service Workers
                component
CVE-2026-16408: Integer overflow in the Audio/Video: Playback
                component
CVE-2026-16409: Invalid pointer in the Security: PSM component
CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT
                component
CVE-2026-16411: Memory safety bugs fixed in Firefox 153
CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and
                Firefox 153
CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38,
                Firefox ESR 140.13 and Firefox 153

Change-Id: I5257f0ea9954099337b4b5beb60e7788a0fc6e05
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-07-26 18:46:34 -07:00
moksh d1de434264 gnu: firefox-l10n: Update to 235fd5b0427bec104e6af4055756b286554fce17.
* gnu/packages/librewolf.scm (firefox-l10n): Update to 235fd5b0427bec104e6af4055756b286554fce17.

Change-Id: Ibf31c8a7a4d9b107afee32e52bb352422d6be988
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-07-26 18:46:31 -07:00
Ian Eure f5358353c8 gnu: librewolf: Update to 152.0.6-1 [security-fixes].
Contains fixes for:
CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly
                component
CVE-2026-15719: Site isolation in the DOM: Navigation component

* gnu/packages/librewolf.scm (librewolf): Update to 152.0.6-1.

Change-Id: Ib130bc8510bcc8c9e25c5bd5b85615c6c24ee2be
2026-07-18 16:42:14 -07:00
Ian Eure fc9f6fedab gnu: firefox-l10n: Update to e42882cfa3ac852e9df3683aed1dc27b3a62b9fb.
* gnu/packages/librewolf.scm (firefox-l10n): Update to e42882cfa3ac852e9df3683aed1dc27b3a62b9fb.

Change-Id: Iaece459886ce59391ea60d58c4e175d11234c70c
2026-07-18 16:42:13 -07:00
Ian Eure b4f4c339f1 gnu: librewolf: Update to 152.0.5-1.
* gnu/packages/librewolf.scm (librewolf): Update to 152.0.5-1.

Change-Id: I92a76d6eb377331b7d7795a375a1393f66c01fc9
2026-07-10 22:05:33 -07:00
Ian Eure 350084736e gnu: firefox-l10n: Update to 6ee6f5c40c1c46d85d49da26ecb5e42ba1167650.
* gnu/packages/librewolf.scm (firefox-l10n): Update to 6ee6f5c40c1c46d85d49da26ecb5e42ba1167650.

Change-Id: Id1873e9d255c3fb9cbf6a37c3664630c0aa41454
2026-07-10 22:05:30 -07:00
Ian Eure 647956378e gnu: librewolf: Update to 152.0.4-1 [security-fixes].
Contains fixes for:
CVE-2026-14241: Memory safety bugs fixed in Firefox 152.0.4

* gnu/packages/librewolf.scm (librewolf): Update to 152.0.4-1.
* gnu/packages/patches/librewolf-neuter-locale-download.patch: Adjust to apply
cleanly.

Change-Id: I80a5b8be81fc178cac1bd7a102cd48ba7b8c72d7
2026-07-02 17:25:39 -07:00
Ian Eure f8771f7500 gnu: firefox-l10n: Update to 3a21e0c6121d869025be23c7aa9da8498354852f.
* gnu/packages/librewolf.scm (firefox-l10n): Update to 3a21e0c6121d869025be23c7aa9da8498354852f.

Change-Id: I967f6b0023abef33acb7af133cf544f2f98f43d9
2026-07-02 17:25:38 -07:00
Ian Eure 3c94ceee91 gnu: librewolf: Update to 152.0.2-1.
* gnu/packages/librewolf.scm (librewolf): Update to 152.0.2-1.

Change-Id: I373c8a0e752b52f213cbe715041f60d65bdaabe3
2026-06-28 08:37:46 -07:00
Ian Eure fd41a6cda6 gnu: firefox-l10n: Update to ec0a48f0301f2c82c2d3fe9fbe07e30869bb345b.
* gnu/packages/librewolf.scm (firefox-l10n): Update to ec0a48f0301f2c82c2d3fe9fbe07e30869bb345b.

Change-Id: Ic7b9e7b5a18a52ffc3e7394af6c6826a4d16fb3e
2026-06-28 08:37:45 -07:00
Ian Eure ecd4ab5994 gnu: librewolf: Update to 152.0.1-1 [security-fixes].
Contains fixes for:
CVE-2026-12289: Privilege escalation in the Graphics: WebRender
                component
CVE-2026-12290: Memory safety bug fixed in Firefox 152
CVE-2026-12291: Use-after-free in the Networking: HTTP component
CVE-2026-12292: Incorrect boundary conditions in the Web Audio
                component
CVE-2026-12293: Use-after-free in the Graphics: WebGPU component
CVE-2026-12294: Sandbox escape in the DOM: Workers component
CVE-2026-12295: Sandbox escape in the DOM: Navigation component
CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing
                component
CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in
                the Networking component
CVE-2026-12298: Memory safety bug fixed in Firefox 152
CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component
CVE-2026-12300: Memory safety bug fixed in Firefox 152
CVE-2026-12301: Memory safety bug fixed in Firefox 152
CVE-2026-12302: Mitigation bypass in the DOM: Security component
CVE-2026-12303: Information disclosure due to incorrect boundary
                conditions in the Graphics: WebGPU component
CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies
                component
CVE-2026-12305: Memory safety bug fixed in Firefox 152
CVE-2026-12306: Memory safety bug fixed in Firefox 152
CVE-2026-12307: Memory safety bug fixed in Firefox 152
CVE-2026-12308: Memory safety bug fixed in Firefox 152
CVE-2026-12309: Memory safety bug fixed in Firefox 152
CVE-2026-12310: Memory safety bug fixed in Firefox 152
CVE-2026-12311: Information disclosure, sandbox escape in the
                Security: Process Sandboxing component
CVE-2026-12312: Memory safety bug fixed in Firefox 152
CVE-2026-12313: Information disclosure, sandbox escape in the
                Security: Process Sandboxing component
CVE-2026-12314: Memory safety bug fixed in Firefox 152
CVE-2026-12315: Mitigation bypass in the DOM: Security component
CVE-2026-12316: Mitigation bypass in the DOM: Security component
CVE-2026-12317: Memory safety bug fixed in Firefox 152
CVE-2026-12318: Incorrect boundary conditions in the Libraries
                component in NSS
CVE-2026-12319: Denial-of-service in the Audio/Video: Playback
                component
CVE-2026-12320: Information disclosure in the Password Manager
                component
CVE-2026-12321: JIT miscompilation in the JavaScript: WebAssembly
                component
CVE-2026-12322: Clickjacking issue in the Widget: Gtk component
CVE-2026-12323: Spoofing issue in the DOM: Core & HTML component
CVE-2026-12324: Incorrect boundary conditions in the Graphics:
                CanvasWebGL component
CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component
CVE-2026-12326: Memory safety bugs fixed in Firefox 152 and
                Thunderbird 152
CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12,
                Thunderbird ESR 140.12, Firefox 152 and Thunderbird
                152
CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37,
                Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox
                152 and Thunderbird 152

gnu: librewolf: Update to 152.0.1-1.

* gnu/packages/librewolf.scm (librewolf): Update to 152.0.1-1.

Change-Id: Ifd4692c316ad7cdaae5466169906ecb1340365dd
2026-06-19 21:45:00 -07:00
moksh ddc7e2fbab gnu: librewolf: Update to 151.0.4-1.
* gnu/packages/librewolf.scm (librewolf): Update to 151.0.4-1.

Change-Id: I2ac2c4cd5ffcc36c6bb57c4f3bbc515d4e2c076c
2026-06-10 22:05:55 -07:00
moksh 63c23eb1be gnu: firefox-l10n: Update to 5cdc7448c1e193ee833b11f5e4f7b3c1ddb2f366.
* gnu/packages/librewolf.scm (firefox-l10n): Update to 5cdc7448c1e193ee833b11f5e4f7b3c1ddb2f366.

Change-Id: I0853f6997ae96e4026f848cc0364b5a7323612c3
2026-06-10 22:05:55 -07:00
moksh 61a36beb4a gnu: librewolf: Update to 151.0.2-1.
* gnu/packages/librewolf.scm (librewolf): Update to 151.0.2-1.

Change-Id: I95a215401d1059035c448caa5847ef1d2b9143cf
2026-05-28 20:17:54 -07:00
moksh a7cc0cf504 gnu: firefox-l10n: Update to a8799feda04a221a2c552576501975662c5350bb.
* gnu/packages/librewolf.scm (firefox-l10n): Update to a8799feda04a221a2c552576501975662c5350bb.

Change-Id: I2c6bffd563c145b707e0039e0cc0b3fdc2dbcada
2026-05-28 20:17:54 -07:00
moksh 0e7f87432b gnu: librewolf: Update to 151.0.1-2 [security-fixes].
* gnu/packages/librewolf.scm (librewolf): Update to 151.0.1-2.

Contains Fixes for:
Firefox 151.0 contains fixes for:
CVE-2026-8945: Sandbox escape in Firefox and Firefox Focus for Android
CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web
               Codecs component
CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component
CVE-2026-8948: Same-origin policy bypass in the DOM: Networking
               component
CVE-2026-8949: Integer overflow in the Widget: Win32 component
CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP
               component
CVE-2026-8951: Spoofing issue in the Toolbar component in Firefox for
               Android
CVE-2026-8952: Privilege escalation in the Application Update
               component
CVE-2026-8953: Sandbox escape due to use-after-free in the Disability
               Access APIs component
CVE-2026-8954: Incorrect boundary conditions, integer overflow in the
               Audio/Video component
CVE-2026-8955: Privilege escalation in the DOM: Workers component
CVE-2026-8956: Integer overflow in the Networking: JAR component
CVE-2026-8957: Privilege escalation in the Enterprise Policies
               component
CVE-2026-8958: Information disclosure, sandbox escape in the Security:
               Process Sandboxing component
CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in
               the Widget: Win32 component
CVE-2026-8960: Spoofing issue in WebExtensions
CVE-2026-8961: Spoofing issue in the Form Autofill component
CVE-2026-8962: Mitigation bypass in the DOM: Security component
CVE-2026-8963: Spoofing issue in the Web Speech component
CVE-2026-8964: Spoofing issue in the Popup Blocker component
CVE-2026-8965: Information disclosure in the DOM: Security component
CVE-2026-8966: Information disclosure in the IP Protection component
CVE-2026-8967: Information disclosure in the Graphics: WebGPU
               component
CVE-2026-8968: Denial-of-service due to invalid pointer in the
               Audio/Video: Web Codecs component
CVE-2026-8969: Mitigation bypass in the DOM: Security component
CVE-2026-8970: Privilege escalation in the Security component
CVE-2026-8971: Same-origin policy bypass in the Networking: JAR
               component
CVE-2026-8972: Privilege escalation in the WebRTC: Audio/Video
               component
CVE-2026-8973: Memory safety bugs fixed in Firefox 151
CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and
               Firefox 151
CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox
               ESR 140.11 and Firefox 151

Change-Id: I7a73e001546ddfa5f2f48ad569f1c60ac807a10a
2026-05-24 19:45:21 -07:00
moksh 6e339966e7 gnu: firefox-l10n: Update to a8799feda04a221a2c552576501975662c5350bb.
* gnu/packages/librewolf.scm (firefox-l10n): Update to a8799feda04a221a2c552576501975662c5350bb.

Change-Id: I8f079c2eb5ccaf9933b47f5ed53de7e578777e44
2026-05-24 19:45:20 -07:00
Ian Eure 0039b976d1 gnu: librewolf: Update to 150.0.3-1 [security-fixes].
Contains fixes for:
CVE-2026-8090: Use-after-free in the DOM: Networking component
CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2,
               Firefox ESR 140.10.2 and Firefox 150.0.2
CVE-2026-8093: Memory safety bugs fixed in Firefox 150.0.2
CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine:
               JIT component
CVE-2026-8389: JIT miscompilation in the JavaScript Engine: JIT
               component
CVE-2026-8390: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-8391: Other issue in the JavaScript Engine component
CVE-2026-8401: Sandbox escape in the Profile Backup component

* gnu/packages/librewolf.scm (librewolf): Update to 150.0.3-1.
2026-05-15 21:33:07 -07:00
Ian Eure 41c8658772 gnu: librewolf: Update to 150.0.1-1 [security-fixes].
Contains fixes for:
CVE-2026-7320: Information disclosure due to incorrect boundary
               conditions in the Audio/Video component
CVE-2026-7322: Memory safety bugs fixed in Firefox ESR 115.35.1,
               Firefox ESR 140.10.1 and Firefox 150.0.1
CVE-2026-7323: Memory safety bugs fixed in Firefox ESR 140.10.1 and
               Firefox 150.0.1
CVE-2026-7324: Memory safety bugs fixed in Firefox 150.0.1

* gnu/packages/librewolf.scm (librewolf): Update to 150.0.1-1.
* gnu/packages/patches/librewolf-150.0-encoding_rs-rust-fix.patch: Delete
file.
* gnu/local.mk (dist_patch_DATA): Remove
librewolf-150.0-encoding_rs-rust-fix.patch.

Change-Id: Ibf081e87d9183c5f04330389da87639ed80a7f77
2026-05-02 09:07:13 -07:00
Ian Eure e5e2aaaf55 gnu: librewolf: Update to 150.0-1. [security-updates]
Contains fixes for:
CVE-2026-6746: Use-after-free in the DOM: Core & HTML component
CVE-2026-6747: Use-after-free in the WebRTC component
CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs
               component
CVE-2026-6749: Information disclosure due to uninitialized memory in
               the Graphics: Canvas2D component
CVE-2026-6750: Privilege escalation in the Graphics: WebRender
               component
CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs
               component
CVE-2026-6752: Incorrect boundary conditions in the WebRTC component
CVE-2026-6753: Incorrect boundary conditions in the WebRTC component
CVE-2026-6754: Use-after-free in the JavaScript Engine component
CVE-2026-6755: Mitigation bypass in the DOM: postMessage component
CVE-2026-6756: Mitigation bypass in Firefox for Android
CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly
               component
CVE-2026-6758: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-6759: Use-after-free in the Widget: Cocoa component
CVE-2026-6760: Mitigation bypass in the Networking: Cookies component
CVE-2026-6761: Privilege escalation in the Networking component
CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component
CVE-2026-6763: Mitigation bypass in the File Handling component
CVE-2026-6764: Incorrect boundary conditions in the DOM: Device
               Interfaces component
CVE-2026-6765: Information disclosure in the Form Autofill component
CVE-2026-6766: Incorrect boundary conditions in the Libraries
               component in NSS
CVE-2026-6767: Other issue in the Libraries component in NSS
CVE-2026-6768: Mitigation bypass in the Networking: Cookies component
CVE-2026-6769: Privilege escalation in the Debugger component
CVE-2026-6770: Other issue in the Storage: IndexedDB component
CVE-2026-6771: Mitigation bypass in the DOM: Security component
CVE-2026-6772: Incorrect boundary conditions in the Libraries
               component in NSS
CVE-2026-6773: Denial-of-service due to integer overflow in the
               Graphics: WebGPU component
CVE-2026-6774: Mitigation bypass in the DOM: Security component
CVE-2026-6775: Incorrect boundary conditions in the WebRTC component
CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking
               component
CVE-2026-6777: Other issue in the Networking: DNS component
CVE-2026-6778: Invalid pointer in the Audio/Video: Playback component
CVE-2026-6779: Other issue in the JavaScript Engine component
CVE-2026-6780: Denial-of-service in the Audio/Video: Playback
               component
CVE-2026-6781: Denial-of-service in the Audio/Video: Playback
               component
CVE-2026-6782: Information disclosure in the IP Protection component
CVE-2026-6783: Incorrect boundary conditions, integer overflow in the
               Audio/Video: Playback component
CVE-2026-6784: Memory safety bugs fixed in Firefox 150 and Thunderbird
               150
CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox
               ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and
               Thunderbird 150
CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10,
               Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150

* gnu/packages/patches/librewolf-150.0-encoding_rs-rust-fix.patch: New file.
* gnu/local.mk: Add new patch to dist_patch_DATA.
* gnu/packages/librewolf.scm (make-librewolf-source): Apply new patch.
* gnu/packages/librewolf.scm (librewolf): Update to 150.0-1.
[arguments #:phases use-mozzarella]: Update Mozzarella URLs.  Fixes #1923.

Change-Id: I7696abc0ac44d689190d9ef1e12704905c11d431
2026-04-25 09:50:42 -07:00
moksh 365ff68f3c gnu: librewolf: Update to 149.0.2-2.
* gnu/packages/librewolf.scm (librewolf): Update to 149.0.2-2.

Change-Id: If3097740c91328ba25dbe30fb79146f9d939d448
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-04-11 20:53:49 -07:00
moksh dc2e36600b gnu: firefox-l10n: Update to 0245ffb160688061f0e0c67ea488bcdfdacbeca4.
* gnu/packages/librewolf.scm (firefox-l10n): Update to 0245ffb160688061f0e0c67ea488bcdfdacbeca4.

Change-Id: I0446ec35a45e31cfd3752c51421e4d3416388fec
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-04-11 20:53:48 -07:00
moksh 21946173a0 gnu: librewolf: Update to 149.0-1 [security-fixes].
* gnu/packages/librewolf.scm (librewolf): Update to 149.0-1.

Contains fixes for:
CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component
CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component
CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component
CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component
CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component
CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component
CVE-2026-4692: Sandbox escape in the Responsive Design Mode component
CVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component
CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component
CVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component
CVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component
CVE-2026-4700: Mitigation bypass in the Networking: HTTP component
CVE-2026-4701: Use-after-free in the JavaScript Engine component
CVE-2026-4722: Privilege escalation in the IPC component
CVE-2026-4702: JIT miscompilation in the JavaScript Engine component
CVE-2026-4723: Use-after-free in the JavaScript Engine component
CVE-2026-4724: Undefined behavior in the Audio/Video component
CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component
CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component
CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component
CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component
CVE-2026-4708: Incorrect boundary conditions in the Graphics component
CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component
CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component
CVE-2026-4711: Use-after-free in the Widget: Cocoa component
CVE-2026-4725: Sandbox escape due to use-after-free in the Graphics: Canvas2D component
CVE-2026-4712: Information disclosure in the Widget: Cocoa component
CVE-2026-4713: Incorrect boundary conditions in the Graphics component
CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component
CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component
CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component
CVE-2026-4717: Privilege escalation in the Netmonitor component
CVE-2026-4726: Denial-of-service in the XML component
CVE-2025-59375: Denial-of-service in the XML component
CVE-2026-4727: Denial-of-service in the Libraries component in NSS
CVE-2026-4728: Spoofing issue in the Privacy: Anti-Tracking component
CVE-2026-4718: Undefined behavior in the WebRTC: Signaling component
CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component
CVE-2026-4720: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVE-2026-4729: Memory safety bugs fixed in Firefox 149 and Thunderbird 149
CVE-2026-4721: Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and
hunderbird 149

Change-Id: I40e76bf852087d71f8df869103c846032e8552c9
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-03-28 21:57:43 -07:00
moksh 23fb319fdd gnu/packages/librewolf: firefox-l10n: Update to d1394212aed0ce0063c0f818aa236e7d4f955ac9.
* gnu/packages/librewolf.scm (firefox-l10n): Update to d1394212aed0ce0063c0f818aa236e7d4f955ac9.

Change-Id: I7e152e1f384d7499aa4a368ca8b20d829d1a69ae
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-03-28 21:57:39 -07:00
Ian Eure e5d5718393 gnu: librewolf: Update to 148.0.2-3.
* gnu/packages/librewolf.scm (librewolf): Update to 148.0.2-3.

Change-Id: Ia8b0c554e7d4da8aa22f60658c24051319f1bb6f
2026-03-21 12:38:55 -07:00
Ian Eure 670c723676 gnu: librewolf: Update to 148.0.2-2 [security-fixes].
Contains fixes for:

CVE-2026-3845: Heap buffer overflow in the Audio/Video: Playback
               component in Firefox for Android
CVE-2026-3846: Same-origin policy bypass in the CSS Parsing and
               Computation component
CVE-2026-3847: Memory safety bugs fixed in Firefox 148.0.2

* gnu/packages/librewolf.scm (librewolf): Update to 148.0.2-2.

Change-Id: Id3868e10d38f5f111bd00bc140a9dc64f132caa9
2026-03-14 16:38:05 -07:00
moksh cf27ff3da3 gnu: librewolf: Update to 148.0-1 [security-fixes].
* gnu/packages/librewolf.scm (librewolf): Update to 148.0-1.
[native-inputs]: Use clang-21 and llvm-21.

Containes fixes for:
CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component
CVE-2026-2794: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
CVE-2026-2758: Use-after-free in the JavaScript: GC component
CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component
CVE-2026-2795: Use-after-free in the JavaScript: GC component
CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
CVE-2026-2761: Sandbox escape in the Graphics: WebRender component
CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component
CVE-2026-2763: Use-after-free in the JavaScript Engine component
CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component
CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-2797: Use-after-free in the JavaScript: GC component
CVE-2026-2765: Use-after-free in the JavaScript Engine component
CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component
CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component
CVE-2026-2798: Use-after-free in the DOM: Core & HTML component
CVE-2026-2769: Use-after-free in the Storage: IndexedDB component
CVE-2026-2799: Use-after-free in the DOM: Core & HTML component
CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component
CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component
CVE-2026-2772: Use-after-free in the Audio/Video: Playback component
CVE-2026-2773: Incorrect boundary conditions in the Web Audio component
CVE-2026-2774: Integer overflow in the Audio/Video component
CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component
CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software
CVE-2026-2777: Privilege escalation in the Messaging System component
CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component
CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component
CVE-2026-2800: Spoofing issue in the WebAuthn component in Firefox for Android
CVE-2026-2780: Privilege escalation in the Netmonitor component
CVE-2026-2781: Integer overflow in the Libraries component in NSS
CVE-2026-2801: Incorrect boundary conditions in the JavaScript: WebAssembly component
CVE-2026-2782: Privilege escalation in the Netmonitor component
CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-2802: Race condition in the JavaScript: GC component
CVE-2026-2803: Information disclosure, mitigation bypass in the Settings UI component
CVE-2026-2784: Mitigation bypass in the DOM: Security component
CVE-2026-2785: Invalid pointer in the JavaScript Engine component
CVE-2026-2804: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-2786: Use-after-free in the JavaScript Engine component
CVE-2026-2805: Invalid pointer in the DOM: Core & HTML component
CVE-2026-2787: Use-after-free in the DOM: Window and Location component
CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component
CVE-2026-2789: Use-after-free in the Graphics: ImageLib component
CVE-2026-2806: Uninitialized memory in the Graphics: Text component
CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component
CVE-2026-2791: Mitigation bypass in the Networking: Cache component
CVE-2026-2807: Memory safety bugs fixed in Firefox 148 and Thunderbird 148
CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird
CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox

Change-Id: I3baa7dee1c8667e8a6fc04e0112c1fddb8ed7d81
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-02-28 19:23:59 -08:00
moksh dd0459d597 gnu: librewolf-bsys6: Update to 274e39ee40592f8bc6ca5d4ee699ec74aeeab983.
* gnu/packages/librewolf.scm (librewolf-bsys6): Update to 274e39ee40592f8bc6ca5d4ee699ec74aeeab983.

Change-Id: I548c901bdc5319d32dec6ccc7a3300063dbcf7c0
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-02-28 19:23:58 -08:00
moksh 0b568bd65c gnu: firefox-l10n: Update to c316776e57fcf5c11054c115054b083ce0790ce7.
* gnu/packages/librewolf.scm (firefox-l10n): Update to c316776e57fcf5c11054c115054b083ce0790ce7.

Change-Id: Ia2677558cb0977f38589454885d2fdd6707f32f8
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-02-28 19:23:57 -08:00
moksh abd5648c14 gnu: librewolf: Update to 147.0.4-1.
contains fixes for:
CVE-2026-2447: Heap buffer overflow in libvpx

* gnu/packages/librewolf.scm (librewolf): Update to 147.0.4-1.

Change-Id: I32fd2b71192434c53bf9f37b59632e2f64137191
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-02-18 21:12:23 -08:00
moksh d46b423c1d gnu: librewolf: Update to 147.0.3-2.
* gnu/packages/librewolf.scm (librewolf): Update to 147.0.3-2.

Change-Id: I0c4c97d86c4f22e46393da93ea89e22b84a29197
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-02-07 12:05:04 -08:00
moksh 28b956178c gnu: librewolf: Update to 147.0.3-1.
* gnu/packages/librewolf.scm (librewolf): Update to 147.0.3-1.

Change-Id: I700dfb3e00467f19105794b6e45c22ff07b26b52
Signed-off-by: Ian Eure <ian@retrospec.tv>
2026-02-06 08:22:37 -08:00
moksh ce49f1c567 gnu: librewolf: Update to 147.0.2-1 [security-fixes].
contains fixes for:
CVE-2026-24868: Mitigation bypass in the Privacy: Anti-Tracking component
CVE-2026-24869: Use-after-free in the Layout: Scrolling and Overflow componentn

* gnu/packages/librewolf.scm (librewolf): Update to 147.0.2-1.

Change-Id: Ie9b9d75d1be09f6e625ed85b7e6950fae27cf050
2026-02-02 10:44:26 -08:00
Ian Eure 2c34e9ccb6 gnu: librewolf: Update to 147.0.1-3 [security-fixes].
Contains fixes for:
CVE-2026-0877: Mitigation bypass in the DOM: Security component
CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in
               the Graphics: CanvasWebGL component
CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in
               the Graphics component
CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics
               component
CVE-2026-0881: Sandbox escape in the Messaging System component
CVE-2026-0882: Use-after-free in the IPC component
CVE-2026-0883: Information disclosure in the Networking component
CVE-2026-0884: Use-after-free in the JavaScript Engine component
CVE-2026-0885: Use-after-free in the JavaScript: GC component
CVE-2026-0886: Incorrect boundary conditions in the Graphics component
CVE-2026-0887: Clickjacking issue, information disclosure in the PDF
               Viewer component
CVE-2026-0888: Information disclosure in the XML component
CVE-2026-0889: Denial-of-service in the DOM: Service Workers component
CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop
               component
CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7,
               Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
CVE-2026-0892: Memory safety bugs fixed in Firefox 147 and Thunderbird
               147

* gnu/packages/librewolf.scm (librewolf-bsys6): New variable.
* gnu/packages/librewolf.scm (make-librewolf-source): Don’t attempt to GPG
sign the source tarball, the key isn’t available.
* gnu/packages/librewolf.scm (librewolf): Update to 147.0.1-3.
[native-inputs] Add librewolf-bsys6.
[phases 'patch-icu-lookup]: Delete.
[phases 'install-desktop-entry]: Use the .desktop file template from librewolf-bsys6.

Change-Id: Ic7ff0197294cbb2485cb8db2f42f4fb499e39277
2026-01-20 18:05:03 -08:00
Ian Eure 679e30988b gnu: firefox-l10n: Update to da03d1507bcec6952b788a21f3cfa95673b1da4c.
* gnu/packages/librewolf.scm (firefox-l10n): Update to da03d1507bcec6952b788a21f3cfa95673b1da4c.

Change-Id: I5a0a62e39bda0a214f6915aef6a730438e596570
2026-01-20 18:05:02 -08:00
moksh cb927b546e gnu: librewolf: Update to 146.0.1-1 [security-fixes].
contains fixes for:
CVE-2025-14860: Use-after-free in the Disability Access APIs component
CVE-2025-14861: Memory safety bugs fixed in Firefox 146.0.1

* gnu/packages/librewolf.scm (librewolf): Update to 146.0.1-1.

Change-Id: I0dc2c26bf6b301cd04ce2897b3688f4a3a102e24
2025-12-20 11:06:07 -08:00
Ian Eure 8cef389d35 gnu: librewolf: Update to 146.0-2 [security-fixes].
Contains fixes for:
CVE-2025-14321: Use-after-free in the WebRTC: Signaling component
CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in
                the Graphics: CanvasWebGL component
CVE-2025-14323: Privilege escalation in the DOM: Notifications
                component
CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT
                component
CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT
                component
CVE-2025-14326: Use-after-free in the Audio/Video: GMP component
CVE-2025-14327: Spoofing issue in the Downloads Panel component
CVE-2025-14328: Privilege escalation in the Netmonitor component
CVE-2025-14329: Privilege escalation in the Netmonitor component
CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT
                component
CVE-2025-14331: Same-origin policy bypass in the Request Handling
                component
CVE-2025-14332: Memory safety bugs fixed in Firefox 146 and
                Thunderbird 146
CVE-2025-14333: Memory safety bugs fixed in Firefox ESR 140.6,
                Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146

* gnu/packages/librewolf.scm (librewolf): Update to 146.0-2.
2025-12-16 06:56:24 -08:00
Ian Eure b0a55661b1 gnu: firefox-l10n: Update to fa4b12c075b42be6652237119d74346d377d2ae4.
* gnu/packages/librewolf.scm (firefox-l10n): Update to fa4b12c075b42be6652237119d74346d377d2ae4.

Change-Id: I25e7c160fd252d67c5e117b0ad48d431c7ee5b45
2025-12-16 06:56:23 -08:00
Ian Eure 4fc5de41a3 gnu: librewolf: Update to 145.0.2-2.
* gnu/packages/librewolf.scm (librewolf): Update to 145.0.2-2.

Change-Id: I5c46804b24892658091fd1a1e40ab307b54654f7
2025-12-03 17:41:37 -08:00
Ian Eure 8cd94366a9 gnu: librewolf-l10n: Update to 38e9598ea1b99b69a240cc1db1d59f4357fcb95d.
* gnu/packages/librewolf.scm (librewolf-l10n): Update to 38e9598ea1b99b69a240cc1db1d59f4357fcb95d.

Change-Id: I70c7ec0e261afa15dfaca7fab399cb42d97606e1
2025-12-03 17:41:34 -08:00
Ian Eure c93b89e591 gnu: librewolf: Update to 145.0.1-2 [security-fixes].
Contains fixes for:
CVE-2025-13021: Incorrect boundary conditions in the Graphics: WebGPU
                component
CVE-2025-13022: Incorrect boundary conditions in the Graphics: WebGPU
                component
CVE-2025-13012: Race condition in the Graphics component
CVE-2025-13023: Sandbox escape due to incorrect boundary conditions in
                the Graphics: WebGPU component
CVE-2025-13016: Incorrect boundary conditions in the JavaScript:
                WebAssembly component
CVE-2025-13024: JIT miscompilation in the JavaScript Engine: JIT
                component
CVE-2025-13025: Incorrect boundary conditions in the Graphics: WebGPU
                component
CVE-2025-13026: Sandbox escape due to incorrect boundary conditions in
                the Graphics: WebGPU component
CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications
                component
CVE-2025-13018: Mitigation bypass in the DOM: Security component
CVE-2025-13019: Same-origin policy bypass in the DOM: Workers
                component
CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component
CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component
CVE-2025-13014: Use-after-free in the Audio/Video component
CVE-2025-13015: Spoofing issue in Firefox
CVE-2025-13027: Memory safety bugs fixed in Firefox 145 and
                Thunderbird 145

* gnu/packages/librewolf.scm (librewolf): Update to 145.0.1-2.

Change-Id: Ibc74847cb0bbf3ca31cd91ebead1459199a1b364
2025-11-25 21:45:56 -08:00
Ian Eure 60b6c5bdc2 gnu: firefox-l10n: Update to 74fe0b1805ed82dd5e27092a7d0f970c68207f2f.
* gnu/packages/librewolf.scm (firefox-l10n): Update to 74fe0b1805ed82dd5e27092a7d0f970c68207f2f.

Change-Id: I7591affa769976cd015959c84c7afbb786fc75c0
2025-11-25 21:45:55 -08:00
Ian Eure 894df5f56b gnu: librewolf: Update to 144.0.2-1 [security-fixes].
Contains fixes for:
CVE-2025-12380: Use-after-free in WebGPU internals triggered from a
                compromised child process

* gnu/packages/librewolf.scm (librewolf): Update to 144.0.2-1.

Change-Id: I20a797097579d8633adefcd2fc7f365d1ea828b0
2025-11-04 16:35:36 -08:00
Ian Eure ba7b96dcd6 gnu: firefox-l10n: Update to 19667931d63ae27d05ebb5701884a5b45ca89976.
* gnu/packages/librewolf.scm (firefox-l10n): Update to 19667931d63ae27d05ebb5701884a5b45ca89976.

Change-Id: Icdab2dfb3629f5c3507c0a77892a207d00d7871e
2025-11-04 16:35:35 -08:00
Maxim Cournoyer 0f39db9c19 Revert "Use mmap for the elf parser, reducing memory usage."
This reverts commit 2c1fe0df11.
2025-10-30 16:19:50 +09:00
Maxim Cournoyer 9d60fdf6a2 Revert "elf: Remove bundled Guile source."
This reverts commit 11cf5b2fe4.
2025-10-30 16:19:49 +09:00
Maxim Cournoyer 11cf5b2fe4 elf: Remove bundled Guile source.
This module has been included in Guile as (system vm elf) since around version
2.1.

* guix/elf.scm: Delete file.
* CODEOWNERS: De-register module.
* Makefile.am (MODULES): Likewise.
* etc/teams.scm (core): Likewise.
* gnu/build/linux-modules.scm: Adjust imports.
* gnu/packages/gnuzilla.scm (icecat-minimal) [modules]: Likewise.
* gnu/packages/librewolf.scm (librewolf): Likewise.
* gnu/packages/sequoia.scm (sequoia): Likewise.
* gnu/packages/tor-browsers.scm (make-torbrowser): Likewise.
* gnu/packages/version-control.scm (hg-commitsigs): Likewise.
* guix/build/debug-link.scm: Likewise.
* guix/build/gnu-build-system.scm: Likewise.
* guix/build/gremlin.scm: Likewise.
* guix/build/meson-build-system.scm: Likewise.
* guix/grafts.scm (graft-derivation/shallow): Likewise.
* guix/scripts/pack.scm (wrapped-package): Likewise.
* tests/debug-link.scm: ("elf-debuglink", "set-debuglink-crc"): Likewise.
* tests/gremlin.scm: Likewise.
* guix/build-system/gnu.scm (%default-gnu-imported-modules): Remove (guix elf).

Change-Id: I86ac4237fdd820a6b54dc0fe7a7d10403a290ef9
2025-10-30 16:13:03 +09:00
Maxim Cournoyer 2c1fe0df11 Use mmap for the elf parser, reducing memory usage.
The `file->bytevector' new procedure uses a memory mapped bytevector, so
parsing the ELF file reads only the sections needed, not the whole file.

* guix/scripts/pack.scm (wrapped-package): Use file->bytevector.
* guix/build/gremlin.scm (file-dynamic-info): Likewise.
(validate-needed-in-runpath): Likewise.
(strip-runpath): Likewise, and write to bytevector directly, avoiding a port.
(set-file-runpath): Likewise.
* tests/gremlin.scm (read-elf): Delete procedure.
("elf-dynamic-info-needed, executable"): Use file-dynamic-info.
("strip-runpath"): Likewise.
("elf-dynamic-info-soname"): Likewise.
 guix/build/debug-link.scm (set-debuglink-crc): Use file->bytevector.
* tests/debug-link.scm (read-elf): Delete procedure.
("elf-debuglink"): Rename to...
("elf-debuglink, no .gnu_debuglink section"): ... this.
("elf-debuglink", "set-debuglink-crc"): Use external store, and adjust to use
file->bytevector.
* gnu/packages/gnuzilla.scm (icecat-minimal) [#:phases]
{build-sandbox-whitelist}: Use `file-runpath'.
* gnu/packages/librewolf.scm (librewolf): Likewise.

Fixes: <https://issues.guix.gnu.org/59365>
Fixes: #1262
Change-Id: I43b77ed0cdc38994ea89d3d401e0d136aa6b187a
2025-10-30 16:13:03 +09:00
Ian Eure 08b7a61448 gnu: librewolf: Update to 144.0-1 [security-fixes].
Firefox 144.0 contains fixes for:
CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance()
CVE-2025-11709: Out of bounds read/write in a privileged process
                triggered by WebGL textures
CVE-2025-11710: Cross-process information leaked due to malicious IPC
                messages
CVE-2025-11711: Some non-writable Object properties could be modified
CVE-2025-11716: Sandboxed iframes allowed links to open in external
                apps (Android only)
CVE-2025-11717: The password edit screen was not hidden in Android
                card view
CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior
                on web resources without a content-type
CVE-2025-11718: Address bar could be spoofed on Android using
                visibilitychange
CVE-2025-11713: Potential user-assisted code execution in “Copy as
                cURL” command
CVE-2025-11719: Use-after-free caused by the native messaging web
                extension API on Windows
CVE-2025-11720: Spoofing risk in Android custom tabs
CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29,
                Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144
                and Thunderbird 144
CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4,
                Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
CVE-2025-11721: Memory safety bug fixed in Firefox 144 and Thunderbird
                144

* gnu/packages/librewolf.scm (librewolf): Update to 144.0-1.

Change-Id: I39e97cde24d820882c79a137997a5252e6e70421
2025-10-21 16:52:39 -07:00