Package firefox-esr: Information

    Source package: firefox-esr
    Version: 140.7.0-alt1
    Build time:  Jan 22, 2026, 06:36 PM in the task #405113
    Category: Networking/WWW
    Report package bug
    License: MPL-2.0
    Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
    Description: 
    Mozilla Firefox is an open-source web browser, designed
    for standards compliance, performance and portability.

    List of RPM packages built from this SRPM:
    firefox-esr (x86_64, i586, aarch64)
    firefox-esr-config-privacy (x86_64, i586, aarch64)
    firefox-esr-debuginfo (x86_64, i586, aarch64)

    Maintainer: Pavel Vasenkov


      1. /dev/shm
      2. /proc
      3. alternatives
      4. browser-plugins-npapi-devel
      5. cbindgen
      6. chrpath
      7. clang17.0
      8. clang17.0-devel
      9. glibc-kernheaders-generic
      10. gst-plugins1.0-devel
      11. gstreamer1.0-devel
      12. libnss-devel-static
      13. libshell
      14. libstdc++-devel
      15. libwireless-devel
      16. lld17.0-devel
      17. llvm17.0-devel
      18. mozilla-common-devel
      19. nasm
      20. node
      21. pkgconfig(alsa)
      22. pkgconfig(aom)
      23. pkgconfig(bzip2)
      24. pkgconfig(cairo)
      25. pkgconfig(dav1d)
      26. pkgconfig(dbus-1)
      27. pkgconfig(dbus-glib-1)
      28. pkgconfig(dri)
      29. pkgconfig(fontconfig)
      30. pkgconfig(freetype2)
      31. pkgconfig(gio-2.0)
      32. pkgconfig(graphite2)
      33. pkgconfig(gtk+-3.0)
      34. pkgconfig(harfbuzz)
      35. pkgconfig(hunspell)
      36. pkgconfig(icu-i18n)
      37. pkgconfig(libcurl)
      38. pkgconfig(libdrm)
      39. pkgconfig(libevent)
      40. pkgconfig(libffi)
      41. pkgconfig(libjpeg)
      42. pkgconfig(libnotify)
      43. pkgconfig(libproxy-1.0)
      44. pkgconfig(libpulse)
      45. pkgconfig(libstartup-notification-1.0)
      46. pkgconfig(nspr) >= 4.35
      47. pkgconfig(nss) >= 3.98
      48. pkgconfig(opus)
      49. pkgconfig(pixman-1)
      50. pkgconfig(vpx)
      51. pkgconfig(x11)
      52. pkgconfig(xcomposite)
      53. pkgconfig(xcursor)
      54. pkgconfig(xdamage)
      55. pkgconfig(xext)
      56. pkgconfig(xft)
      57. pkgconfig(xi)
      58. pkgconfig(xkbcommon)
      59. pkgconfig(xrandr)
      60. pkgconfig(xscrnsaver)
      61. pkgconfig(xt)
      62. pkgconfig(xtst)
      63. pkgconfig(zlib)
      64. python3(click)
      65. python3(configobj)
      66. python3(curses)
      67. python3(hamcrest)
      68. python3(setuptools)
      69. python3(pip)
      70. python3(sqlite3)
      71. python3-base
      72. rust >= 1.65.0
      73. rust-cargo >= 1.65.0
      74. unzip
      75. rpm-build-firefox
      76. xorg-cf-files
      77. rpm-macros-alternatives
      78. yasm
      79. zip

    Last changed


    Jan. 14, 2026 Pavel Vasenkov 140.7.0-alt1
    - New ESR version.
    - Security fixes:
      + CVE-2026-0877 Mitigation bypass in the DOM: Security component
      + CVE-2026-0878 Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
      + CVE-2026-0879 Sandbox escape due to incorrect boundary conditions in the Graphics component
      + CVE-2026-0880 Sandbox escape due to integer overflow in the Graphics component
      + CVE-2026-0882 Use-after-free in the IPC component
      + CVE-2025-14327 Spoofing issue in the Downloads Panel component
      + CVE-2026-0883 Information disclosure in the Networking component
      + CVE-2026-0884 Use-after-free in the JavaScript Engine component
      + CVE-2026-0885 Use-after-free in the JavaScript: GC component
      + CVE-2026-0886 Incorrect boundary conditions in the Graphics component
      + CVE-2026-0887 Clickjacking issue, information disclosure in the PDF Viewer component
      + CVE-2026-0890 Spoofing issue in the DOM: Copy & Paste and Drag & Drop component
      + CVE-2026-0891 Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147
    Dec. 10, 2025 Pavel Vasenkov 140.6.0-alt1
    - New ESR version.
    - Security fixes:
      + CVE-2025-14321 Use-after-free in the WebRTC: Signaling component
      + CVE-2025-14322 Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
      + CVE-2025-14323 Privilege escalation in the DOM: Notifications component
      + CVE-2025-14324 JIT miscompilation in the JavaScript Engine: JIT component
      + CVE-2025-14325 JIT miscompilation in the JavaScript Engine: JIT component
      + CVE-2025-14328 Privilege escalation in the Netmonitor component
      + CVE-2025-14329 Privilege escalation in the Netmonitor component
      + CVE-2025-14330 JIT miscompilation in the JavaScript Engine: JIT component
      + CVE-2025-14331 Same-origin policy bypass in the Request Handling component
      + CVE-2025-14333 Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
    Nov. 14, 2025 Pavel Vasenkov 140.5.0-alt1
    - New ESR version.
    - Security fixes:
      + CVE-2025-13012 Race condition in the Graphics component
      + CVE-2025-13016 Incorrect boundary conditions in the JavaScript: WebAssembly component
      + CVE-2025-13017 Same-origin policy bypass in the DOM: Notifications component
      + CVE-2025-13018 Mitigation bypass in the DOM: Security component
      + CVE-2025-13019 Same-origin policy bypass in the DOM: Workers component
      + CVE-2025-13013 Mitigation bypass in the DOM: Core & HTML component
      + CVE-2025-13020 Use-after-free in the WebRTC: Audio/Video component
      + CVE-2025-13014 Use-after-free in the Audio/Video component
      + CVE-2025-13015 Spoofing issue in Firefox
    - provides x-www-browser (Closes: #44717).