Path to this page:
./
www/firefox153,
Web browser with support for extensions (version 153ESR)
Branch: CURRENT,
Version: 153.2.0,
Package name: firefox153-153.2.0,
Maintainer: ryoonMozilla Firefox is a free, open-source and cross-platform web browser
for Windows, Linux, MacOS X and many other operating systems.
It is fast and easy to use, and offers many advantages over other web
browsers, such as tabbed browsing and the ability to block pop-up
windows.
Firefox also offers excellent bookmark and history management, and it
can be extended by developers using industry standards such as XML,
CSS, JavaScript, C++, etc. Many extensions are available.
Note: Due to upstream's trademark policies, this package identifies as
"Nightly" rather than "Firefox" by default.
This package provides Firefox 153 Extended Support Release.
Package options: sunaudio, webrtc
Master sites: (Expand)
Filesize: 788775.07 KB
Version history: (Expand)
- (2026-09-01) Updated to version: firefox153-153.2.0
- (2026-08-27) Package added to pkgsrc.se, version firefox153-153.1.0 (created)
CVS history: (Expand)
2026-09-01 18:09:24 by David H. Gutteridge | Files touched by this commit (2) |  |
Log message:
firefox153: update to 153.2
Mozilla Foundation Security Advisory 2026-85
Security Vulnerabilities fixed in Firefox ESR 153.2
Announced
September 1, 2026
Impact
high
Products
Firefox ESR
Fixed in
Firefox ESR 153.2
#CVE-2026-75874: Sandbox escape in the Remote Settings Client component
Reporter
crixer
Impact
high
References
Bug 2039972
#CVE-2026-84118: Use-after-free in the JavaScript: GC component
Reporter
x0e
Impact
high
References
Bug 2057457
#CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation \
component
Reporter
Yaqoub Aldurayhim
Impact
high
References
Bug 2057817
#CVE-2026-84120: Use-after-free in the Audio/Video component
Reporter
Ukyo Akai
Impact
high
References
Bug 2058911
#CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component
Reporter
Yaqoub Aldurayhim
Impact
high
References
Bug 2059018
#CVE-2026-84122: Use-after-free in the Audio/Video component
Reporter
Hyeonjun Ahn
Impact
high
References
Bug 2059965
#CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: \
WebGPU component
Reporter
Yaqoub Aldurayhim
Impact
high
References
Bug 2060047
#CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
Reporter
Hyeonjun Ahn
Impact
high
References
Bug 2061110
#CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
Reporter
Yaqoub Aldurayhim
Impact
high
References
Bug 2063871
#CVE-2026-74952: Privilege escalation in the Application Update component
Reporter
Tomoya Nakanishi
Impact
moderate
References
Bug 2021757
#CVE-2026-84129: Site isolation issue in the DOM: Navigation component
Reporter
Yaqoub Aldurayhim
Impact
moderate
References
Bug 2055028
#CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
Reporter
5up3rh3i
Impact
moderate
References
Bug 2057834
#CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics \
component
Reporter
navapon
Impact
moderate
References
Bug 2060008
#CVE-2026-84132: Information disclosure in the Networking: HTTP component
Reporter
Shu Takahashi
Impact
moderate
References
Bug 2063020
#CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component
Reporter
pakhunov.anton.n
Impact
low
References
Bug 2032388
#CVE-2026-84134: Other issue in the Profile Backup component
Reporter
5up3rh3i
Impact
low
References
Bug 2044882
#CVE-2026-84136: Other issue in the DOM: Navigation component
Reporter
Apentota
Impact
low
References
Bug 2048699
#CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
Reporter
Riski Muhammad Ivan
Impact
low
References
Bug 2051146
#CVE-2026-84139: Clickjacking issue in the DOM: Events component
Reporter
Long Nguyen
Impact
low
References
Bug 2060153
#CVE-2026-84140: Site isolation issue in the DOM: Navigation component
Reporter
Mohamed Mbarek
Impact
low
References
Bug 2063780
#CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
Reporter
nguyentuanhung1149
Impact
low
References
Bug 2063994
#CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 \
and Firefox ESR 140.15
Reporter
Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
Impact
high
Description
Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Firefox ESR \
140.14. Some of these bugs showed evidence of memory corruption or another \
security-relevant defect and we presume that with enough effort some of these \
could have been exploited.
References
High Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2 \
and Firefox ESR 140.15
Moderate Severity internally found bugs fixed in Firefox 155, Firefox ESR \
153.2 and Firefox ESR 140.15
Low Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2 \
and Firefox ESR 140.15
#CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
Reporter
Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
Impact
high
Description
Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of \
these bugs showed evidence of memory corruption or another security-relevant \
defect and we presume that with enough effort some of these could have been \
exploited.
References
High Severity internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
Moderate Severity internally found bugs fixed in Firefox 155 and Firefox ESR \
153.2
Low Severity internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
#CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, \
Firefox ESR 140.15 and Firefox ESR 115.40
Reporter
Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
Impact
high
Description
Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR \
140.14 and Firefox ESR 115.39. Some of these bugs showed evidence of memory \
corruption or another security-relevant defect and we presume that with enough \
effort some of these could have been exploited.
References
High Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, \
Firefox ESR 140.15 and Firefox ESR 115.40
Moderate Severity internally found bugs fixed in Firefox 155, Firefox ESR \
153.2, Firefox ESR 140.15 and Firefox ESR 115.40
Low Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, \
Firefox ESR 140.15 and Firefox ESR 115.40
|
| 2026-08-27 18:33:53 by David H. Gutteridge | Files touched by this commit (1) |
Log message:
firefox153: fix Linux packaging
|
| 2026-08-27 03:23:18 by David H. Gutteridge | Files touched by this commit (72) |
Log message:
firefox153: import Firefox 153.1 as www/firefox153
Mozilla Firefox is a free, open-source and cross-platform web browser
for Windows, Linux, MacOS X and many other operating systems.
It is fast and easy to use, and offers many advantages over other web
browsers, such as tabbed browsing and the ability to block pop-up
windows.
Firefox also offers excellent bookmark and history management, and it
can be extended by developers using industry standards such as XML,
CSS, JavaScript, C++, etc. Many extensions are available.
Note: Due to upstream's trademark policies, this package identifies as
"Nightly" rather than "Firefox" by default.
This package provides Firefox 153 Extended Support Release.
|