Package firefox: Information

  • Default inline alert: Version in the repository: 149.0.2-alt1

Source package: firefox
Version: 148.0-alt1
Latest version according to Repology
Build time:  Feb 25, 2026, 06:58 PM in the task #409187
Category: Networking/WWW
Report package bug
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
Mozilla Firefox is an open-source web browser, designed
for standards compliance, performance and portability.

List of RPM packages built from this SRPM:
firefox (x86_64, aarch64)
firefox-config-privacy (x86_64, aarch64)
firefox-debuginfo (x86_64, aarch64)

Maintainer: Ajrat Makhmutov



    1. /dev/shm
    2. /proc
    3. alternatives
    4. browser-plugins-npapi-devel
    5. cbindgen
    6. chrpath
    7. clang17.0
    8. clang17.0-devel
    9. libnss-devel-static
    10. glibc-kernheaders-generic
    11. gst-plugins1.0-devel
    12. gstreamer1.0-devel
    13. libshell
    14. libstdc++-devel
    15. libwireless-devel
    16. python3(pip)
    17. lld17.0-devel
    18. llvm17.0-devel
    19. mozilla-common-devel
    20. python3(setuptools)
    21. nasm
    22. python3(sqlite3)
    23. node
    24. python3-base
    25. pkgconfig(vpx)
    26. pkgconfig(x11)
    27. pkgconfig(xcomposite)
    28. pkgconfig(xcursor)
    29. pkgconfig(xdamage)
    30. rpm-build-firefox
    31. pkgconfig(xext)
    32. pkgconfig(xft)
    33. pkgconfig(xi)
    34. pkgconfig(xkbcommon)
    35. pkgconfig(xrandr)
    36. pkgconfig(xscrnsaver)
    37. pkgconfig(xt)
    38. pkgconfig(xtst)
    39. pkgconfig(zlib)
    40. python3(click)
    41. rpm-macros-alternatives
    42. pkgconfig(alsa)
    43. pkgconfig(aom)
    44. pkgconfig(bzip2)
    45. pkgconfig(cairo)
    46. pkgconfig(dav1d)
    47. pkgconfig(dbus-1)
    48. pkgconfig(dbus-glib-1)
    49. pkgconfig(dri)
    50. python3(hamcrest)
    51. pkgconfig(fontconfig)
    52. pkgconfig(freetype2)
    53. pkgconfig(gio-2.0)
    54. python3(curses)
    55. pkgconfig(graphite2)
    56. pkgconfig(gtk+-3.0)
    57. pkgconfig(harfbuzz)
    58. pkgconfig(hunspell)
    59. pkgconfig(icu-i18n)
    60. pkgconfig(libcurl)
    61. pkgconfig(libdrm)
    62. pkgconfig(libevent)
    63. pkgconfig(libffi)
    64. pkgconfig(libjpeg)
    65. pkgconfig(libnotify)
    66. pkgconfig(libproxy-1.0)
    67. pkgconfig(libpulse)
    68. pkgconfig(libstartup-notification-1.0)
    69. pkgconfig(nspr) >= 4.35
    70. pkgconfig(nss) >= 3.98
    71. pkgconfig(opus)
    72. pkgconfig(pixman-1)
    73. unzip
    74. rust >= 1.65.0
    75. rust-cargo >= 1.65.0
    76. xorg-cf-files
    77. yasm
    78. zip

Last changed


Feb. 25, 2026 Ajrat Makhmutov 148.0-alt1
- New version (148.0).
- Fixes:
  + CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component
  + CVE-2026-2794: Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android
  + CVE-2026-2758: Use-after-free in the JavaScript: GC component
  + CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component
  + CVE-2026-2795: Use-after-free in the JavaScript: GC component
  + CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
  + CVE-2026-2761: Sandbox escape in the Graphics: WebRender component
  + CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component
  + CVE-2026-2763: Use-after-free in the JavaScript Engine component
  + CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component
  + CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component
  + CVE-2026-2797: Use-after-free in the JavaScript: GC component
  + CVE-2026-2765: Use-after-free in the JavaScript Engine component
  + CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component
  + CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component
  + CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component
  + CVE-2026-2798: Use-after-free in the DOM: Core & HTML component
  + CVE-2026-2769: Use-after-free in the Storage: IndexedDB component
  + CVE-2026-2799: Use-after-free in the DOM: Core & HTML component
  + CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component
  + CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component
  + CVE-2026-2772: Use-after-free in the Audio/Video: Playback component
  + CVE-2026-2773: Incorrect boundary conditions in the Web Audio component
  + CVE-2026-2774: Integer overflow in the Audio/Video component
  + CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component
  + CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software
  + CVE-2026-2777: Privilege escalation in the Messaging System component
  + CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component
  + CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component
  + CVE-2026-2800: Spoofing issue in the WebAuthn component in Firefox for Android
  + CVE-2026-2780: Privilege escalation in the Netmonitor component
  + CVE-2026-2781: Integer overflow in the Libraries component in NSS
  + CVE-2026-2801: Incorrect boundary conditions in the JavaScript: WebAssembly component
  + CVE-2026-2782: Privilege escalation in the Netmonitor component
  + CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component
  + CVE-2026-2802: Race condition in the JavaScript: GC component
  + CVE-2026-2803: Information disclosure, mitigation bypass in the Settings UI component
  + CVE-2026-2784: Mitigation bypass in the DOM: Security component
  + CVE-2026-2785: Invalid pointer in the JavaScript Engine component
  + CVE-2026-2804: Use-after-free in the JavaScript: WebAssembly component
  + CVE-2026-2786: Use-after-free in the JavaScript Engine component
  + CVE-2026-2805: Invalid pointer in the DOM: Core & HTML component
  + CVE-2026-2787: Use-after-free in the DOM: Window and Location component
  + CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component
  + CVE-2026-2789: Use-after-free in the Graphics: ImageLib component
  + CVE-2026-2806: Uninitialized memory in the Graphics: Text component
  + CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component
  + CVE-2026-2791: Mitigation bypass in the Networking: Cache component
  + CVE-2026-2807: Memory safety bugs fixed in Firefox 148 and Thunderbird 148
  + CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
  + CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
Feb. 20, 2026 Ajrat Makhmutov 147.0.4-alt1
- New version (147.0.4).
- Fixes:
  + CVE-2026-2447: Heap buffer overflow in libvpx
Jan. 28, 2026 Ajrat Makhmutov 147.0.2-alt1
- New version (147.0.2).
- Fixes:
  + CVE-2026-24868: Mitigation bypass in the Privacy: Anti-Tracking component
  + CVE-2026-24869: Use-after-free in the Layout: Scrolling and Overflow component