Package firefox: Information

  • Default inline alert: Version in the repository: 149.0-alt1

Source package: firefox
Version: 148.0-alt2
Build time:  Mar 16, 2026, 03:51 PM in the task #409232
Category: Networking/WWW
Report package bug
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
Mozilla Firefox is an open-source web browser, designed
for standards compliance, performance and portability.

List of RPM packages built from this SRPM:
firefox (x86_64, aarch64)
firefox-config-privacy (x86_64, aarch64)
firefox-debuginfo (x86_64, aarch64)

Maintainer: Ajrat Makhmutov


    1. /dev/shm
    2. mozilla-common-devel
    3. pkgconfig(libcurl)
    4. pkgconfig(libdrm)
    5. pkgconfig(libevent)
    6. pkgconfig(libffi)
    7. rust >= 1.65.0
    8. rust-cargo >= 1.65.0
    9. python3(hamcrest)
    10. gst-plugins1.0-devel
    11. /proc
    12. pkgconfig(libjpeg)
    13. pkgconfig(libnotify)
    14. pkgconfig(libproxy-1.0)
    15. pkgconfig(libpulse)
    16. nasm
    17. unzip
    18. pkgconfig(libstartup-notification-1.0)
    19. gstreamer1.0-devel
    20. alternatives
    21. python3(pip)
    22. node
    23. pkgconfig(nspr) >= 4.35
    24. pkgconfig(nss) >= 3.98
    25. pkgconfig(opus)
    26. pkgconfig(pixman-1)
    27. xorg-cf-files
    28. browser-plugins-npapi-devel
    29. pkgconfig(vpx)
    30. pkgconfig(x11)
    31. pkgconfig(xcomposite)
    32. pkgconfig(xcursor)
    33. pkgconfig(xdamage)
    34. pkgconfig(alsa)
    35. pkgconfig(aom)
    36. pkgconfig(bzip2)
    37. pkgconfig(cairo)
    38. yasm
    39. cbindgen
    40. python3(setuptools)
    41. pkgconfig(dav1d)
    42. pkgconfig(dbus-1)
    43. pkgconfig(dbus-glib-1)
    44. pkgconfig(dri)
    45. pkgconfig(xext)
    46. pkgconfig(xft)
    47. pkgconfig(xi)
    48. pkgconfig(xkbcommon)
    49. pkgconfig(xrandr)
    50. pkgconfig(xscrnsaver)
    51. pkgconfig(xt)
    52. pkgconfig(xtst)
    53. pkgconfig(zlib)
    54. zip
    55. python3(sqlite3)
    56. pkgconfig(fontconfig)
    57. pkgconfig(freetype2)
    58. pkgconfig(gio-2.0)
    59. chrpath
    60. python3(click)
    61. pkgconfig(graphite2)
    62. pkgconfig(gtk+-3.0)
    63. python3-base
    64. python3(curses)
    65. clang17.0
    66. clang17.0-devel
    67. pkgconfig(harfbuzz)
    68. pkgconfig(hunspell)
    69. pkgconfig(icu-i18n)
    70. glibc-kernheaders-generic
    71. rpm-build-firefox
    72. rpm-macros-alternatives
    73. libnss-devel-static
    74. libshell
    75. libstdc++-devel
    76. libwireless-devel
    77. lld17.0-devel
    78. llvm17.0-devel

Last changed


Feb. 28, 2026 Ajrat Makhmutov 148.0-alt2
- Update l10n for the 148.
Feb. 25, 2026 Ajrat Makhmutov 148.0-alt1
- New version (148.0).
- Fixes:
  + CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component
  + CVE-2026-2794: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
  + CVE-2026-2758: Use-after-free in the JavaScript: GC component
  + CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component
  + CVE-2026-2795: Use-after-free in the JavaScript: GC component
  + CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
  + CVE-2026-2761: Sandbox escape in the Graphics: WebRender component
  + CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component
  + CVE-2026-2763: Use-after-free in the JavaScript Engine component
  + CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component
  + CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component
  + CVE-2026-2797: Use-after-free in the JavaScript: GC component
  + CVE-2026-2765: Use-after-free in the JavaScript Engine component
  + CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component
  + CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component
  + CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component
  + CVE-2026-2798: Use-after-free in the DOM: Core & HTML component
  + CVE-2026-2769: Use-after-free in the Storage: IndexedDB component
  + CVE-2026-2799: Use-after-free in the DOM: Core & HTML component
  + CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component
  + CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component
  + CVE-2026-2772: Use-after-free in the Audio/Video: Playback component
  + CVE-2026-2773: Incorrect boundary conditions in the Web Audio component
  + CVE-2026-2774: Integer overflow in the Audio/Video component
  + CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component
  + CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software
  + CVE-2026-2777: Privilege escalation in the Messaging System component
  + CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component
  + CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component
  + CVE-2026-2800: Spoofing issue in the WebAuthn component in Firefox for Android
  + CVE-2026-2780: Privilege escalation in the Netmonitor component
  + CVE-2026-2781: Integer overflow in the Libraries component in NSS
  + CVE-2026-2801: Incorrect boundary conditions in the JavaScript: WebAssembly component
  + CVE-2026-2782: Privilege escalation in the Netmonitor component
  + CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component
  + CVE-2026-2802: Race condition in the JavaScript: GC component
  + CVE-2026-2803: Information disclosure, mitigation bypass in the Settings UI component
  + CVE-2026-2784: Mitigation bypass in the DOM: Security component
  + CVE-2026-2785: Invalid pointer in the JavaScript Engine component
  + CVE-2026-2804: Use-after-free in the JavaScript: WebAssembly component
  + CVE-2026-2786: Use-after-free in the JavaScript Engine component
  + CVE-2026-2805: Invalid pointer in the DOM: Core & HTML component
  + CVE-2026-2787: Use-after-free in the DOM: Window and Location component
  + CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component
  + CVE-2026-2789: Use-after-free in the Graphics: ImageLib component
  + CVE-2026-2806: Uninitialized memory in the Graphics: Text component
  + CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component
  + CVE-2026-2791: Mitigation bypass in the Networking: Cache component
  + CVE-2026-2807: Memory safety bugs fixed in Firefox 148 and Thunderbird 148
  + CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
  + CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
Feb. 20, 2026 Ajrat Makhmutov 147.0.4-alt1
- New version (147.0.4).
- Fixes:
  + CVE-2026-2447: Heap buffer overflow in libvpx