Home / mailingsPDF  

[SECURITY] [DSA 6101-1] firefox-esr security update

Posted on 15 January 2026
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6101-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
January 15, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : firefox-esr
CVE ID : CVE-2025-14327 CVE-2026-0877 CVE-2026-0878 CVE-2026-0879
CVE-2026-0880 CVE-2026-0882 CVE-2026-0883 CVE-2026-0884
CVE-2026-0885 CVE-2026-0886 CVE-2026-0887 CVE-2026-0890
CVE-2026-0891

Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code, sandbox escape, information disclosure or spoofing.

For the oldstable distribution (bookworm), these problems have been fixed
in version 140.7.0esr-1~deb12u1.

For the stable distribution (trixie), these problems have been fixed in
version 140.7.0esr-1~deb13u1.

We recommend that you upgrade your firefox-esr packages.

For the detailed security status of firefox-esr please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/firefox-esr

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP