* gnu/packages/librewolf.scm (librewolf): Update to 153.0.3-1.
(firefox-l10n): Update to 6795ea14a5bd5ed79a930e6759823c7236476ae4.
(make-librewolf-source): Make ff_source_tarball substitution tolerant of
whitespace, and preserve what whitespace is present.
Change-Id: Ifaba8b5bbaba829ad62b8c7507fa877dc3bd78b4
* gnu/packages/librewolf.scm (librewolf): Update to 153.0-2.
Firefox 153.0 contains fixes for:
CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation
component
CVE-2026-16350: Incorrect boundary conditions in the Audio/Video:
cubeb component
CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
CVE-2026-16351: Sandbox escape due to use-after-free in the DOM:
Navigation component
CVE-2026-16352: Sandbox escape due to use-after-free in the Disability
Access APIs component
CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly
component
CVE-2026-16364: Incorrect boundary conditions in the Audio/Video:
Playback component
CVE-2026-16365: Privilege escalation in the DOM: Workers component
CVE-2026-16366: Privilege escalation in the DOM: Navigation component
CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL)
component
CVE-2026-16354: Information disclosure in the Graphics: ImageLib
component
CVE-2026-16367: Sandbox escape due to invalid pointer in the
Disability Access APIs component
CVE-2026-16368: Incorrect boundary conditions in the JavaScript:
WebAssembly component
CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly
component
CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2026-16356: Sandbox escape due to use-after-free in the Disability
Access APIs component
CVE-2026-16357: Incorrect boundary conditions in the Graphics
component
CVE-2026-16370: Mitigation bypass in the DOM: Networking component
CVE-2026-16371: Privilege escalation in the DOM: Navigation component
CVE-2026-16372: Privilege escalation in the DOM: Content Processes
component
CVE-2026-16373: Information disclosure in the Privacy component in
Firefox for Android
CVE-2026-16374: Information disclosure in the Framework component in
DevTools
CVE-2026-16375: Site isolation issue in the Networking: HTTP component
CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
CVE-2026-16377: Mitigation bypass in the PDF Viewer component
CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop
component
CVE-2026-16379: Privilege escalation in the DOM: Content Processes
component
CVE-2026-16358: Site isolation issue in the Graphics: WebRender
component
CVE-2026-16380: Mitigation bypass in the Networking component
CVE-2026-16381: Same-origin policy bypass in the Networking: DNS
component
CVE-2026-16382: Mitigation bypass in the DOM: Service Workers
component
CVE-2026-16383: Mitigation bypass in the DOM: Networking component
CVE-2026-16384: Information disclosure due to uninitialized memory in
the Graphics: WebGPU component
CVE-2026-16385: Information disclosure due to uninitialized memory in
the Graphics: WebGPU component
CVE-2026-16386: Information disclosure due to uninitialized memory in
the Graphics: WebGPU component
CVE-2026-16387: Site isolation issue in the Networking component
CVE-2026-16388: Sandbox escape in the DOM: Networking component
CVE-2026-16389: Incorrect boundary conditions, integer overflow in the
Libraries component in NSS
CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
CVE-2026-16391: Information disclosure in the Storage: IndexedDB
component
CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU
component
CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
component
CVE-2026-16394: Mitigation bypass in the DOM: Security component
CVE-2026-16395: Integer overflow in the Audio/Video component
CVE-2026-16396: Privilege escalation in WebExtensions
CVE-2026-16397: Clickjacking issue in the WebExtensions component in
Firefox for Android
CVE-2026-16398: Site isolation issue in the Graphics component
CVE-2026-16399: Site isolation issue in the DOM: Navigation component
CVE-2026-16400: Information disclosure in the DOM: Security component
CVE-2026-16401: Privilege escalation in the Data Loss Prevention
component
CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
CVE-2026-16403: Spoofing issue in the Address Bar component
CVE-2026-16404: Spoofing issue in Firefox for Android
CVE-2026-16405: Information disclosure in the Networking: WebSockets
component
CVE-2026-16406: Mitigation bypass in the Networking component
CVE-2026-16407: Mitigation bypass in the DOM: Service Workers
component
CVE-2026-16408: Integer overflow in the Audio/Video: Playback
component
CVE-2026-16409: Invalid pointer in the Security: PSM component
CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2026-16411: Memory safety bugs fixed in Firefox 153
CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and
Firefox 153
CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38,
Firefox ESR 140.13 and Firefox 153
Change-Id: I5257f0ea9954099337b4b5beb60e7788a0fc6e05
Signed-off-by: Ian Eure <ian@retrospec.tv>
Contains fixes for:
CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly
component
CVE-2026-15719: Site isolation in the DOM: Navigation component
* gnu/packages/librewolf.scm (librewolf): Update to 152.0.6-1.
Change-Id: Ib130bc8510bcc8c9e25c5bd5b85615c6c24ee2be
Contains fixes for:
CVE-2026-12289: Privilege escalation in the Graphics: WebRender
component
CVE-2026-12290: Memory safety bug fixed in Firefox 152
CVE-2026-12291: Use-after-free in the Networking: HTTP component
CVE-2026-12292: Incorrect boundary conditions in the Web Audio
component
CVE-2026-12293: Use-after-free in the Graphics: WebGPU component
CVE-2026-12294: Sandbox escape in the DOM: Workers component
CVE-2026-12295: Sandbox escape in the DOM: Navigation component
CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing
component
CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in
the Networking component
CVE-2026-12298: Memory safety bug fixed in Firefox 152
CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component
CVE-2026-12300: Memory safety bug fixed in Firefox 152
CVE-2026-12301: Memory safety bug fixed in Firefox 152
CVE-2026-12302: Mitigation bypass in the DOM: Security component
CVE-2026-12303: Information disclosure due to incorrect boundary
conditions in the Graphics: WebGPU component
CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies
component
CVE-2026-12305: Memory safety bug fixed in Firefox 152
CVE-2026-12306: Memory safety bug fixed in Firefox 152
CVE-2026-12307: Memory safety bug fixed in Firefox 152
CVE-2026-12308: Memory safety bug fixed in Firefox 152
CVE-2026-12309: Memory safety bug fixed in Firefox 152
CVE-2026-12310: Memory safety bug fixed in Firefox 152
CVE-2026-12311: Information disclosure, sandbox escape in the
Security: Process Sandboxing component
CVE-2026-12312: Memory safety bug fixed in Firefox 152
CVE-2026-12313: Information disclosure, sandbox escape in the
Security: Process Sandboxing component
CVE-2026-12314: Memory safety bug fixed in Firefox 152
CVE-2026-12315: Mitigation bypass in the DOM: Security component
CVE-2026-12316: Mitigation bypass in the DOM: Security component
CVE-2026-12317: Memory safety bug fixed in Firefox 152
CVE-2026-12318: Incorrect boundary conditions in the Libraries
component in NSS
CVE-2026-12319: Denial-of-service in the Audio/Video: Playback
component
CVE-2026-12320: Information disclosure in the Password Manager
component
CVE-2026-12321: JIT miscompilation in the JavaScript: WebAssembly
component
CVE-2026-12322: Clickjacking issue in the Widget: Gtk component
CVE-2026-12323: Spoofing issue in the DOM: Core & HTML component
CVE-2026-12324: Incorrect boundary conditions in the Graphics:
CanvasWebGL component
CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component
CVE-2026-12326: Memory safety bugs fixed in Firefox 152 and
Thunderbird 152
CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12,
Thunderbird ESR 140.12, Firefox 152 and Thunderbird
152
CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37,
Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox
152 and Thunderbird 152
gnu: librewolf: Update to 152.0.1-1.
* gnu/packages/librewolf.scm (librewolf): Update to 152.0.1-1.
Change-Id: Ifd4692c316ad7cdaae5466169906ecb1340365dd
* gnu/packages/librewolf.scm (librewolf): Update to 151.0.1-2.
Contains Fixes for:
Firefox 151.0 contains fixes for:
CVE-2026-8945: Sandbox escape in Firefox and Firefox Focus for Android
CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web
Codecs component
CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component
CVE-2026-8948: Same-origin policy bypass in the DOM: Networking
component
CVE-2026-8949: Integer overflow in the Widget: Win32 component
CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP
component
CVE-2026-8951: Spoofing issue in the Toolbar component in Firefox for
Android
CVE-2026-8952: Privilege escalation in the Application Update
component
CVE-2026-8953: Sandbox escape due to use-after-free in the Disability
Access APIs component
CVE-2026-8954: Incorrect boundary conditions, integer overflow in the
Audio/Video component
CVE-2026-8955: Privilege escalation in the DOM: Workers component
CVE-2026-8956: Integer overflow in the Networking: JAR component
CVE-2026-8957: Privilege escalation in the Enterprise Policies
component
CVE-2026-8958: Information disclosure, sandbox escape in the Security:
Process Sandboxing component
CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in
the Widget: Win32 component
CVE-2026-8960: Spoofing issue in WebExtensions
CVE-2026-8961: Spoofing issue in the Form Autofill component
CVE-2026-8962: Mitigation bypass in the DOM: Security component
CVE-2026-8963: Spoofing issue in the Web Speech component
CVE-2026-8964: Spoofing issue in the Popup Blocker component
CVE-2026-8965: Information disclosure in the DOM: Security component
CVE-2026-8966: Information disclosure in the IP Protection component
CVE-2026-8967: Information disclosure in the Graphics: WebGPU
component
CVE-2026-8968: Denial-of-service due to invalid pointer in the
Audio/Video: Web Codecs component
CVE-2026-8969: Mitigation bypass in the DOM: Security component
CVE-2026-8970: Privilege escalation in the Security component
CVE-2026-8971: Same-origin policy bypass in the Networking: JAR
component
CVE-2026-8972: Privilege escalation in the WebRTC: Audio/Video
component
CVE-2026-8973: Memory safety bugs fixed in Firefox 151
CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and
Firefox 151
CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox
ESR 140.11 and Firefox 151
Change-Id: I7a73e001546ddfa5f2f48ad569f1c60ac807a10a
Contains fixes for:
CVE-2026-8090: Use-after-free in the DOM: Networking component
CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2,
Firefox ESR 140.10.2 and Firefox 150.0.2
CVE-2026-8093: Memory safety bugs fixed in Firefox 150.0.2
CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine:
JIT component
CVE-2026-8389: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2026-8390: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-8391: Other issue in the JavaScript Engine component
CVE-2026-8401: Sandbox escape in the Profile Backup component
* gnu/packages/librewolf.scm (librewolf): Update to 150.0.3-1.
Contains fixes for:
CVE-2026-6746: Use-after-free in the DOM: Core & HTML component
CVE-2026-6747: Use-after-free in the WebRTC component
CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs
component
CVE-2026-6749: Information disclosure due to uninitialized memory in
the Graphics: Canvas2D component
CVE-2026-6750: Privilege escalation in the Graphics: WebRender
component
CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs
component
CVE-2026-6752: Incorrect boundary conditions in the WebRTC component
CVE-2026-6753: Incorrect boundary conditions in the WebRTC component
CVE-2026-6754: Use-after-free in the JavaScript Engine component
CVE-2026-6755: Mitigation bypass in the DOM: postMessage component
CVE-2026-6756: Mitigation bypass in Firefox for Android
CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly
component
CVE-2026-6758: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-6759: Use-after-free in the Widget: Cocoa component
CVE-2026-6760: Mitigation bypass in the Networking: Cookies component
CVE-2026-6761: Privilege escalation in the Networking component
CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component
CVE-2026-6763: Mitigation bypass in the File Handling component
CVE-2026-6764: Incorrect boundary conditions in the DOM: Device
Interfaces component
CVE-2026-6765: Information disclosure in the Form Autofill component
CVE-2026-6766: Incorrect boundary conditions in the Libraries
component in NSS
CVE-2026-6767: Other issue in the Libraries component in NSS
CVE-2026-6768: Mitigation bypass in the Networking: Cookies component
CVE-2026-6769: Privilege escalation in the Debugger component
CVE-2026-6770: Other issue in the Storage: IndexedDB component
CVE-2026-6771: Mitigation bypass in the DOM: Security component
CVE-2026-6772: Incorrect boundary conditions in the Libraries
component in NSS
CVE-2026-6773: Denial-of-service due to integer overflow in the
Graphics: WebGPU component
CVE-2026-6774: Mitigation bypass in the DOM: Security component
CVE-2026-6775: Incorrect boundary conditions in the WebRTC component
CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking
component
CVE-2026-6777: Other issue in the Networking: DNS component
CVE-2026-6778: Invalid pointer in the Audio/Video: Playback component
CVE-2026-6779: Other issue in the JavaScript Engine component
CVE-2026-6780: Denial-of-service in the Audio/Video: Playback
component
CVE-2026-6781: Denial-of-service in the Audio/Video: Playback
component
CVE-2026-6782: Information disclosure in the IP Protection component
CVE-2026-6783: Incorrect boundary conditions, integer overflow in the
Audio/Video: Playback component
CVE-2026-6784: Memory safety bugs fixed in Firefox 150 and Thunderbird
150
CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox
ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and
Thunderbird 150
CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10,
Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
* gnu/packages/patches/librewolf-150.0-encoding_rs-rust-fix.patch: New file.
* gnu/local.mk: Add new patch to dist_patch_DATA.
* gnu/packages/librewolf.scm (make-librewolf-source): Apply new patch.
* gnu/packages/librewolf.scm (librewolf): Update to 150.0-1.
[arguments #:phases use-mozzarella]: Update Mozzarella URLs. Fixes#1923.
Change-Id: I7696abc0ac44d689190d9ef1e12704905c11d431
* gnu/packages/librewolf.scm (librewolf): Update to 149.0-1.
Contains fixes for:
CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component
CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component
CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component
CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component
CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component
CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component
CVE-2026-4692: Sandbox escape in the Responsive Design Mode component
CVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component
CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component
CVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component
CVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component
CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component
CVE-2026-4700: Mitigation bypass in the Networking: HTTP component
CVE-2026-4701: Use-after-free in the JavaScript Engine component
CVE-2026-4722: Privilege escalation in the IPC component
CVE-2026-4702: JIT miscompilation in the JavaScript Engine component
CVE-2026-4723: Use-after-free in the JavaScript Engine component
CVE-2026-4724: Undefined behavior in the Audio/Video component
CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component
CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component
CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component
CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component
CVE-2026-4708: Incorrect boundary conditions in the Graphics component
CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component
CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component
CVE-2026-4711: Use-after-free in the Widget: Cocoa component
CVE-2026-4725: Sandbox escape due to use-after-free in the Graphics: Canvas2D component
CVE-2026-4712: Information disclosure in the Widget: Cocoa component
CVE-2026-4713: Incorrect boundary conditions in the Graphics component
CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component
CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component
CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component
CVE-2026-4717: Privilege escalation in the Netmonitor component
CVE-2026-4726: Denial-of-service in the XML component
CVE-2025-59375: Denial-of-service in the XML component
CVE-2026-4727: Denial-of-service in the Libraries component in NSS
CVE-2026-4728: Spoofing issue in the Privacy: Anti-Tracking component
CVE-2026-4718: Undefined behavior in the WebRTC: Signaling component
CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component
CVE-2026-4720: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
CVE-2026-4729: Memory safety bugs fixed in Firefox 149 and Thunderbird 149
CVE-2026-4721: Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and
hunderbird 149
Change-Id: I40e76bf852087d71f8df869103c846032e8552c9
Signed-off-by: Ian Eure <ian@retrospec.tv>
Contains fixes for:
CVE-2026-3845: Heap buffer overflow in the Audio/Video: Playback
component in Firefox for Android
CVE-2026-3846: Same-origin policy bypass in the CSS Parsing and
Computation component
CVE-2026-3847: Memory safety bugs fixed in Firefox 148.0.2
* gnu/packages/librewolf.scm (librewolf): Update to 148.0.2-2.
Change-Id: Id3868e10d38f5f111bd00bc140a9dc64f132caa9
* gnu/packages/librewolf.scm (librewolf): Update to 148.0-1.
[native-inputs]: Use clang-21 and llvm-21.
Containes fixes for:
CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component
CVE-2026-2794: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
CVE-2026-2758: Use-after-free in the JavaScript: GC component
CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component
CVE-2026-2795: Use-after-free in the JavaScript: GC component
CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
CVE-2026-2761: Sandbox escape in the Graphics: WebRender component
CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component
CVE-2026-2763: Use-after-free in the JavaScript Engine component
CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component
CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-2797: Use-after-free in the JavaScript: GC component
CVE-2026-2765: Use-after-free in the JavaScript Engine component
CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component
CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component
CVE-2026-2798: Use-after-free in the DOM: Core & HTML component
CVE-2026-2769: Use-after-free in the Storage: IndexedDB component
CVE-2026-2799: Use-after-free in the DOM: Core & HTML component
CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component
CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component
CVE-2026-2772: Use-after-free in the Audio/Video: Playback component
CVE-2026-2773: Incorrect boundary conditions in the Web Audio component
CVE-2026-2774: Integer overflow in the Audio/Video component
CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component
CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software
CVE-2026-2777: Privilege escalation in the Messaging System component
CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component
CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component
CVE-2026-2800: Spoofing issue in the WebAuthn component in Firefox for Android
CVE-2026-2780: Privilege escalation in the Netmonitor component
CVE-2026-2781: Integer overflow in the Libraries component in NSS
CVE-2026-2801: Incorrect boundary conditions in the JavaScript: WebAssembly component
CVE-2026-2782: Privilege escalation in the Netmonitor component
CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-2802: Race condition in the JavaScript: GC component
CVE-2026-2803: Information disclosure, mitigation bypass in the Settings UI component
CVE-2026-2784: Mitigation bypass in the DOM: Security component
CVE-2026-2785: Invalid pointer in the JavaScript Engine component
CVE-2026-2804: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-2786: Use-after-free in the JavaScript Engine component
CVE-2026-2805: Invalid pointer in the DOM: Core & HTML component
CVE-2026-2787: Use-after-free in the DOM: Window and Location component
CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component
CVE-2026-2789: Use-after-free in the Graphics: ImageLib component
CVE-2026-2806: Uninitialized memory in the Graphics: Text component
CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component
CVE-2026-2791: Mitigation bypass in the Networking: Cache component
CVE-2026-2807: Memory safety bugs fixed in Firefox 148 and Thunderbird 148
CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird
CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox
Change-Id: I3baa7dee1c8667e8a6fc04e0112c1fddb8ed7d81
Signed-off-by: Ian Eure <ian@retrospec.tv>
contains fixes for:
CVE-2026-24868: Mitigation bypass in the Privacy: Anti-Tracking component
CVE-2026-24869: Use-after-free in the Layout: Scrolling and Overflow componentn
* gnu/packages/librewolf.scm (librewolf): Update to 147.0.2-1.
Change-Id: Ie9b9d75d1be09f6e625ed85b7e6950fae27cf050
Contains fixes for:
CVE-2026-0877: Mitigation bypass in the DOM: Security component
CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in
the Graphics: CanvasWebGL component
CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in
the Graphics component
CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics
component
CVE-2026-0881: Sandbox escape in the Messaging System component
CVE-2026-0882: Use-after-free in the IPC component
CVE-2026-0883: Information disclosure in the Networking component
CVE-2026-0884: Use-after-free in the JavaScript Engine component
CVE-2026-0885: Use-after-free in the JavaScript: GC component
CVE-2026-0886: Incorrect boundary conditions in the Graphics component
CVE-2026-0887: Clickjacking issue, information disclosure in the PDF
Viewer component
CVE-2026-0888: Information disclosure in the XML component
CVE-2026-0889: Denial-of-service in the DOM: Service Workers component
CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop
component
CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7,
Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
CVE-2026-0892: Memory safety bugs fixed in Firefox 147 and Thunderbird
147
* gnu/packages/librewolf.scm (librewolf-bsys6): New variable.
* gnu/packages/librewolf.scm (make-librewolf-source): Don’t attempt to GPG
sign the source tarball, the key isn’t available.
* gnu/packages/librewolf.scm (librewolf): Update to 147.0.1-3.
[native-inputs] Add librewolf-bsys6.
[phases 'patch-icu-lookup]: Delete.
[phases 'install-desktop-entry]: Use the .desktop file template from librewolf-bsys6.
Change-Id: Ic7ff0197294cbb2485cb8db2f42f4fb499e39277
Contains fixes for:
CVE-2025-14321: Use-after-free in the WebRTC: Signaling component
CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in
the Graphics: CanvasWebGL component
CVE-2025-14323: Privilege escalation in the DOM: Notifications
component
CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2025-14326: Use-after-free in the Audio/Video: GMP component
CVE-2025-14327: Spoofing issue in the Downloads Panel component
CVE-2025-14328: Privilege escalation in the Netmonitor component
CVE-2025-14329: Privilege escalation in the Netmonitor component
CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2025-14331: Same-origin policy bypass in the Request Handling
component
CVE-2025-14332: Memory safety bugs fixed in Firefox 146 and
Thunderbird 146
CVE-2025-14333: Memory safety bugs fixed in Firefox ESR 140.6,
Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
* gnu/packages/librewolf.scm (librewolf): Update to 146.0-2.
Contains fixes for:
CVE-2025-13021: Incorrect boundary conditions in the Graphics: WebGPU
component
CVE-2025-13022: Incorrect boundary conditions in the Graphics: WebGPU
component
CVE-2025-13012: Race condition in the Graphics component
CVE-2025-13023: Sandbox escape due to incorrect boundary conditions in
the Graphics: WebGPU component
CVE-2025-13016: Incorrect boundary conditions in the JavaScript:
WebAssembly component
CVE-2025-13024: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2025-13025: Incorrect boundary conditions in the Graphics: WebGPU
component
CVE-2025-13026: Sandbox escape due to incorrect boundary conditions in
the Graphics: WebGPU component
CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications
component
CVE-2025-13018: Mitigation bypass in the DOM: Security component
CVE-2025-13019: Same-origin policy bypass in the DOM: Workers
component
CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component
CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component
CVE-2025-13014: Use-after-free in the Audio/Video component
CVE-2025-13015: Spoofing issue in Firefox
CVE-2025-13027: Memory safety bugs fixed in Firefox 145 and
Thunderbird 145
* gnu/packages/librewolf.scm (librewolf): Update to 145.0.1-2.
Change-Id: Ibc74847cb0bbf3ca31cd91ebead1459199a1b364
Contains fixes for:
CVE-2025-12380: Use-after-free in WebGPU internals triggered from a
compromised child process
* gnu/packages/librewolf.scm (librewolf): Update to 144.0.2-1.
Change-Id: I20a797097579d8633adefcd2fc7f365d1ea828b0
The `file->bytevector' new procedure uses a memory mapped bytevector, so
parsing the ELF file reads only the sections needed, not the whole file.
* guix/scripts/pack.scm (wrapped-package): Use file->bytevector.
* guix/build/gremlin.scm (file-dynamic-info): Likewise.
(validate-needed-in-runpath): Likewise.
(strip-runpath): Likewise, and write to bytevector directly, avoiding a port.
(set-file-runpath): Likewise.
* tests/gremlin.scm (read-elf): Delete procedure.
("elf-dynamic-info-needed, executable"): Use file-dynamic-info.
("strip-runpath"): Likewise.
("elf-dynamic-info-soname"): Likewise.
guix/build/debug-link.scm (set-debuglink-crc): Use file->bytevector.
* tests/debug-link.scm (read-elf): Delete procedure.
("elf-debuglink"): Rename to...
("elf-debuglink, no .gnu_debuglink section"): ... this.
("elf-debuglink", "set-debuglink-crc"): Use external store, and adjust to use
file->bytevector.
* gnu/packages/gnuzilla.scm (icecat-minimal) [#:phases]
{build-sandbox-whitelist}: Use `file-runpath'.
* gnu/packages/librewolf.scm (librewolf): Likewise.
Fixes: <https://issues.guix.gnu.org/59365>
Fixes: #1262
Change-Id: I43b77ed0cdc38994ea89d3d401e0d136aa6b187a
Firefox 144.0 contains fixes for:
CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance()
CVE-2025-11709: Out of bounds read/write in a privileged process
triggered by WebGL textures
CVE-2025-11710: Cross-process information leaked due to malicious IPC
messages
CVE-2025-11711: Some non-writable Object properties could be modified
CVE-2025-11716: Sandboxed iframes allowed links to open in external
apps (Android only)
CVE-2025-11717: The password edit screen was not hidden in Android
card view
CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior
on web resources without a content-type
CVE-2025-11718: Address bar could be spoofed on Android using
visibilitychange
CVE-2025-11713: Potential user-assisted code execution in “Copy as
cURL” command
CVE-2025-11719: Use-after-free caused by the native messaging web
extension API on Windows
CVE-2025-11720: Spoofing risk in Android custom tabs
CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29,
Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144
and Thunderbird 144
CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4,
Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
CVE-2025-11721: Memory safety bug fixed in Firefox 144 and Thunderbird
144
* gnu/packages/librewolf.scm (librewolf): Update to 144.0-1.
Change-Id: I39e97cde24d820882c79a137997a5252e6e70421