Package firefox-esr: Information

    Source package: firefox-esr
    Version: 140.7.0-alt3
    Latest version according to Repology
    Build time:  Jan 24, 2026, 03:45 PM in the task #405832
    Category: Networking/WWW
    Report package bug
    License: MPL-2.0
    Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
    Description: 
    Mozilla Firefox is an open-source web browser, designed
    for standards compliance, performance and portability.

    List of RPM packages built from this SRPM:
    firefox-esr (x86_64, i586, aarch64)
    firefox-esr-config-privacy (x86_64, i586, aarch64)
    firefox-esr-debuginfo (x86_64, i586, aarch64)

    Maintainer: Michael Shigorin



      1. /dev/shm
      2. /proc
      3. alternatives
      4. browser-plugins-npapi-devel
      5. glibc-kernheaders-generic
      6. cbindgen
      7. chrpath
      8. clang17.0
      9. clang17.0-devel
      10. gst-plugins1.0-devel
      11. gstreamer1.0-devel
      12. libnss-devel-static
      13. python3(pip)
      14. python3(click)
      15. libshell
      16. libwireless-devel
      17. python3(configobj)
      18. libstdc++-devel
      19. pkgconfig(alsa)
      20. pkgconfig(aom)
      21. pkgconfig(bzip2)
      22. pkgconfig(cairo)
      23. pkgconfig(dav1d)
      24. pkgconfig(dbus-1)
      25. pkgconfig(dbus-glib-1)
      26. pkgconfig(dri)
      27. pkgconfig(fontconfig)
      28. pkgconfig(freetype2)
      29. pkgconfig(gio-2.0)
      30. pkgconfig(graphite2)
      31. python3(curses)
      32. python3(setuptools)
      33. lld17.0-devel
      34. llvm17.0-devel
      35. pkgconfig(gtk+-3.0)
      36. pkgconfig(harfbuzz)
      37. pkgconfig(hunspell)
      38. pkgconfig(icu-i18n)
      39. pkgconfig(libcurl)
      40. pkgconfig(libdrm)
      41. pkgconfig(libevent)
      42. pkgconfig(libffi)
      43. pkgconfig(libjpeg)
      44. pkgconfig(libnotify)
      45. pkgconfig(libproxy-1.0)
      46. pkgconfig(libpulse)
      47. pkgconfig(libstartup-notification-1.0)
      48. pkgconfig(nspr) >= 4.35
      49. pkgconfig(nss) >= 3.98
      50. pkgconfig(opus)
      51. pkgconfig(pixman-1)
      52. python3(sqlite3)
      53. pkgconfig(vpx)
      54. pkgconfig(x11)
      55. pkgconfig(xcomposite)
      56. pkgconfig(xcursor)
      57. pkgconfig(xdamage)
      58. pkgconfig(xext)
      59. pkgconfig(xft)
      60. pkgconfig(xi)
      61. pkgconfig(xkbcommon)
      62. pkgconfig(xrandr)
      63. pkgconfig(xscrnsaver)
      64. pkgconfig(xt)
      65. pkgconfig(xtst)
      66. pkgconfig(zlib)
      67. python3(hamcrest)
      68. mozilla-common-devel
      69. python3-base
      70. rpm-build-firefox
      71. nasm
      72. node
      73. rpm-macros-alternatives
      74. rust >= 1.65.0
      75. rust-cargo >= 1.65.0
      76. unzip
      77. xorg-cf-files
      78. yasm
      79. zip

    Last changed


    Jan. 22, 2026 Michael Shigorin 140.7.0-alt3
    - Fix "new version means new blank profile" (Closes: #57602)
      + thanks NixOS guys, see http://github.com/NixOS/nixpkgs/pull/119849
    Jan. 22, 2026 Michael Shigorin 140.7.0-alt2
    - Get yandex search back through default policy
      (Closes: #45190; see also: #43516; thanks Ruslan Gilfanov).
    Jan. 14, 2026 Pavel Vasenkov 140.7.0-alt1
    - New ESR version.
    - Security fixes:
      + CVE-2026-0877 Mitigation bypass in the DOM: Security component
      + CVE-2026-0878 Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
      + CVE-2026-0879 Sandbox escape due to incorrect boundary conditions in the Graphics component
      + CVE-2026-0880 Sandbox escape due to integer overflow in the Graphics component
      + CVE-2026-0882 Use-after-free in the IPC component
      + CVE-2025-14327 Spoofing issue in the Downloads Panel component
      + CVE-2026-0883 Information disclosure in the Networking component
      + CVE-2026-0884 Use-after-free in the JavaScript Engine component
      + CVE-2026-0885 Use-after-free in the JavaScript: GC component
      + CVE-2026-0886 Incorrect boundary conditions in the Graphics component
      + CVE-2026-0887 Clickjacking issue, information disclosure in the PDF Viewer component
      + CVE-2026-0890 Spoofing issue in the DOM: Copy & Paste and Drag & Drop component
      + CVE-2026-0891 Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147