SUSE SLED15: MozillaFirefox / MozillaFirefox-branding-SLE / MozillaFirefox-devel / etc (SUSE-SU-2026:4156-1)

critical Nessus Plugin ID 346212

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4156-1 advisory.

Changes in MozillaFirefox:

Firefox Extended Support Release 153.2.0 ESR

* Fixed: Various security fixes.

MFSA 2026-85 (bsc#1278001):

* CVE-2026-75874: Sandbox escape in the Remote Settings Client component
* CVE-2026-84118: Use-after-free in the JavaScript: GC component
* CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component
* CVE-2026-84120: Use-after-free in the Audio/Video component
* CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component
* CVE-2026-84122: Use-after-free in the Audio/Video component
* CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics:
WebGPU component
* CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
* CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
* CVE-2026-74952: Privilege escalation in the Application Update component
* CVE-2026-84129: Site isolation issue in the DOM: Navigation component
* CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
* CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component
* CVE-2026-84132: Information disclosure in the Networking: HTTP component
* CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component
* CVE-2026-84134: Other issue in the Profile Backup component
* CVE-2026-84136: Other issue in the DOM: Navigation component
* CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
* CVE-2026-84139: Clickjacking issue in the DOM: Events component
* CVE-2026-84140: Site isolation issue in the DOM: Navigation component
* CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
* CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
* CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
* CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40

* Fixed: Various security fixes.

MFSA 2026-77 (bsc#1274867):
* CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
* CVE-2026-74935: Privilege escalation in the DOM: Networking component
* CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
* CVE-2026-74937: Use-after-free in the JavaScript: GC component
* CVE-2026-74938: Mitigation bypass in the JavaScript: GC component
* CVE-2026-74939: Privilege escalation in the DOM: Navigation component
* CVE-2026-74940: Use-after-free in the Graphics: Text component
* CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component
* CVE-2026-74942: Privilege escalation in the Remote Settings Client component
* CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
* CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
* CVE-2026-74945: Information disclosure in the Graphics: Text component
* CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
* CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component
* CVE-2026-74948: Information disclosure in the Graphics component
* CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics:
Canvas2D component
* CVE-2026-74950: Privilege escalation in the Downloads API component
* CVE-2026-74953: Privilege escalation in the Networking: Cookies component
* CVE-2026-74954: Information disclosure due to side-channel in the Storage:
Cache API component
* CVE-2026-74955: Privilege escalation in the Request Handling component
* CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component
* CVE-2026-74957: Mitigation bypass in the Safe Browsing component
* CVE-2026-74958: Information disclosure in the WebRTC component
* CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
* CVE-2026-74960: Site isolation issue in the WebExtensions component
* CVE-2026-74961: Side-channel in the Web Audio component
* CVE-2026-74962: Site isolation issue in the Networking: Cookies component
* CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component
* CVE-2026-74964: Integer overflow in the Graphics component
* CVE-2026-74965: Privilege escalation in the Shell Integration component
* CVE-2026-74966: Information disclosure in the Form Autofill component
* CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component
* CVE-2026-74968: Site isolation issue in the Graphics: WebRender component
* CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
* CVE-2026-74970: Site isolation issue in the Graphics component
* CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component
* CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component
* CVE-2026-74973: Race condition, use-after-free in the Graphics component
* CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
* CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-74977: Integer overflow in the Graphics component
* CVE-2026-74978: Clickjacking issue in the Widget component
* CVE-2026-74979: Mitigation bypass in the Add-ons Manager component
* CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component
* CVE-2026-74982: Denial-of-service in the Widget component
* CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
* CVE-2026-74984: Race condition in the JavaScript Engine component
* CVE-2026-74985: Privilege escalation in the Enterprise Policies component
* CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component
* CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
* CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154
* CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

- Firefox Extended Support Release 153.0esr ESR

* New: ## General
- Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose.
Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data.
- Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs.
- The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type.
- Firefox now supports copying links directly to highlighted text on a webpage for easier sharing.
- Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences.
* New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy.
* New: ## Sidebar and Tabs
- Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar.
- Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options.
- Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab.
- Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action.
- A Send Tab toolbar button is now available through Customize Toolbar.
* New: ## Security & Privacy
- Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes.
- Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission.
- Firefox now uses Safe Browsing V5 for phishing and malware protection.
- Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk.
- Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility.
* New: ## Translations
- Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality.
- A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox.
* New: ## Accessibility
- Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs.
* New: ## Windows
- Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar.
- Firefox web apps are also available for Microsoft Store installations.
- Firefox now better integrates with Windows location permissions when websites request geolocation access.
* New: ## macOS
- Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser.
- WebGPU is now enabled by default on Apple Silicon Macs.
* New: ## Linux
- Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays.
- Firefox no longer requires a restart after package manager updates and uses less memory on Linux.
- Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions.
* HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views.
- WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs.
- Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling.
* Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy.
- Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications.
- Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/.
* Fixed: Various security fixes.

MFSA 2026-68 (bsc#1271649):

* CVE-2026-16349:
Same-origin policy bypass in the DOM: Navigation component
* CVE-2026-16350:
Incorrect boundary conditions in the Audio/Video: cubeb component
* CVE-2026-16362:
Use-after-free in the WebRTC: Audio/Video component
* CVE-2026-16351:
Sandbox escape due to use-after-free in the DOM: Navigation component
* CVE-2026-16352:
Sandbox escape due to use-after-free in the Disability Access APIs component
* CVE-2026-16363:
JIT miscompilation in the JavaScript: WebAssembly component
* CVE-2026-16364:
Incorrect boundary conditions in the Audio/Video: Playback component
* CVE-2026-16365:
Privilege escalation in the DOM: Workers component
* CVE-2026-16366:
Privilege escalation in the DOM: Navigation component
* CVE-2026-16353:
Invalid pointer in the DOM: Bindings (WebIDL) component
* CVE-2026-16354:
Information disclosure in the Graphics: ImageLib component
* CVE-2026-16367:
Sandbox escape due to invalid pointer in the Disability Access APIs component
* CVE-2026-16368:
Incorrect boundary conditions in the JavaScript: WebAssembly component
* CVE-2026-16369:
Integer overflow in the JavaScript: WebAssembly component
* CVE-2026-16355:
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16356:
Sandbox escape due to use-after-free in the Disability Access APIs component
* CVE-2026-16357:
Incorrect boundary conditions in the Graphics component
* CVE-2026-16370:
Mitigation bypass in the DOM: Networking component
* CVE-2026-16371:
Privilege escalation in the DOM: Navigation component
* CVE-2026-16372:
Privilege escalation in the DOM: Content Processes component
* CVE-2026-16373:
Information disclosure in the Privacy component in Firefox for Android
* CVE-2026-16374:
Information disclosure in the Framework component in DevTools
* CVE-2026-16375:
Site isolation issue in the Networking: HTTP component
* CVE-2026-16376:
Denial-of-service in the Graphics: WebGPU component
* CVE-2026-16377:
Mitigation bypass in the PDF Viewer component
* CVE-2026-16378:
Other issue in the DOM: Copy & Paste and Drag & Drop component
* CVE-2026-16379:
Privilege escalation in the DOM: Content Processes component
* CVE-2026-16358:
Site isolation issue in the Graphics: WebRender component
* CVE-2026-16380:
Mitigation bypass in the Networking component
* CVE-2026-16381:
Same-origin policy bypass in the Networking: DNS component
* CVE-2026-16382:
Mitigation bypass in the DOM: Service Workers component
* CVE-2026-16383:
Mitigation bypass in the DOM: Networking component
* CVE-2026-16384:
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
* CVE-2026-16385:
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
* CVE-2026-16386:
Information disclosure due to uninitialized memory in the Graphics: WebGPU component
* CVE-2026-16387:
Site isolation issue in the Networking component
* CVE-2026-16388:
Sandbox escape in the DOM: Networking component
* CVE-2026-16389:
Incorrect boundary conditions, integer overflow in the Libraries component in NSS
* CVE-2026-16390:
Mitigation bypass in the Enterprise Policies component
* CVE-2026-16391:
Information disclosure in the Storage: IndexedDB component
* CVE-2026-16392:
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16393:
Incorrect boundary conditions in the Graphics: WebGPU component
* CVE-2026-16359:
Incorrect boundary conditions in the Audio/Video: GMP component
* CVE-2026-16394:
Mitigation bypass in the DOM: Security component
* CVE-2026-16395:
Integer overflow in the Audio/Video component
* CVE-2026-16396:
Privilege escalation in WebExtensions
* CVE-2026-16397:
Clickjacking issue in the WebExtensions component in Firefox for Android
* CVE-2026-16398:
Site isolation issue in the Graphics component
* CVE-2026-16399:
Site isolation issue in the DOM: Navigation component
* CVE-2026-16400:
Information disclosure in the DOM: Security component
* CVE-2026-16401:
Privilege escalation in the Data Loss Prevention component
* CVE-2026-16402:
Integer overflow in the Graphics: ImageLib component
* CVE-2026-16403:
Spoofing issue in the Address Bar component
* CVE-2026-16404:
Spoofing issue in Firefox for Android
* CVE-2026-16405:
Information disclosure in the Networking: WebSockets component
* CVE-2026-16406:
Mitigation bypass in the Networking component
* CVE-2026-16407:
Mitigation bypass in the DOM: Service Workers component
* CVE-2026-16408:
Integer overflow in the Audio/Video: Playback component
* CVE-2026-16409:
Invalid pointer in the Security: PSM component
* CVE-2026-16410:
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-16411:
Memory safety bugs fixed in Firefox 153
* CVE-2026-16412:
Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
* CVE-2026-16360:
Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153

* Fixed: Various security fixes.

MFSA 2026-76 (bsc#1274867):

* CVE-2026-74934:
Site isolation issue in the Graphics: CanvasWebGL component
* CVE-2026-74935:
Privilege escalation in the DOM: Networking component
* CVE-2026-74936:
Use-after-free in the JavaScript: WebAssembly component
* CVE-2026-74939:
Privilege escalation in the DOM: Navigation component
* CVE-2026-74940:
Use-after-free in the Graphics: Text component
* CVE-2026-74941:
Privilege escalation in the Graphics: CanvasWebGL component
* CVE-2026-74942:
Privilege escalation in the Remote Settings Client component
* CVE-2026-74943:
Use-after-free in the Graphics: ImageLib component
* CVE-2026-74944:
Use-after-free in the DOM: Core & HTML component
* CVE-2026-74945:
Information disclosure in the Graphics: Text component
* CVE-2026-74946:
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
* CVE-2026-74948:
Information disclosure in the Graphics component
* CVE-2026-74949:
Privilege escalation due to use-after-free in the Graphics:
Canvas2D component
* CVE-2026-74953:
Privilege escalation in the Networking: Cookies component
* CVE-2026-74957:
Mitigation bypass in the Safe Browsing component
* CVE-2026-74959:
Mitigation bypass in the Storage: Cache API component
* CVE-2026-74960:
Site isolation issue in the WebExtensions component
* CVE-2026-74962:
Site isolation issue in the Networking: Cookies component
* CVE-2026-74963:
Same-origin policy bypass in the Networking: Cookies component
* CVE-2026-74964:
Integer overflow in the Graphics component
* CVE-2026-74965:
Privilege escalation in the Shell Integration component
* CVE-2026-74967:
Same-origin policy bypass in the Audio/Video: Playback component
* CVE-2026-74969:
Use-after-free in the Layout: Text and Fonts component
* CVE-2026-74971:
Information disclosure in the DOM: UI Events & Focus Handling component
* CVE-2026-74972:
Information disclosure in the DOM: Push Subscriptions component
* CVE-2026-74973:
Race condition, use-after-free in the Graphics component
* CVE-2026-74974:
Same-origin policy bypass in the Graphics: ImageLib component
* CVE-2026-74976:
JIT miscompilation in the JavaScript Engine: JIT component
* CVE-2026-74983:
Mitigation bypass in the Data Loss Prevention component
* CVE-2026-74987:
Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
* CVE-2026-74990:
Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Changes in rust-cbindgen:

- Update to version v0.29.4+git0:
* Bump version.
* tests: Add some tests for constant enums.
* ir: Add support for arrays.
* ir: Allow constant literals with enum variants.
* ir: Use Path for ConstExprs.
* Bump version to 0.29.3 and update CHANGES doc
* tests: Fix tests with modern gcc.
* Use C++ fixed-type enumeration syntax under C23 (or higher) as well
* Allow `pub` access to `ReprType` fields

- Update to version 0.29.2+git0:
* ci: Add a meta job to block the merge queue on it.
* Check for CMSE ABI's as well
* Fix doc attribute parsing to properly handle block comments
* Expose the line_endings config option to use with the builder
* fix env in workflow file
* use env to pass output parameters
* Explicitly request serde's std features to avoid issues with newer toml versions.
* Account for master -> main rename.
* Update changelog and bump version.
* enum: Track dependencies properly in enumerations.

- Update to version 0.29.2+git0:
* Explicitly request serde's std features to avoid issues with newer toml versions.
* Account for master -> main rename.
* Update changelog and bump version.
* enum: Track dependencies properly in enumerations.
* Allow must_use if a reason is specified
* constant: Handle cfg in associated constants.
* tests: Add a test for bitflags + disjoint cfg.
* Remove 'display' feature from the toml crate
* DOC: Add metatensor
* Fix #1085 - Incorrect detection of duplicated constants
* chore: More clippy fixes.
* docs: Correct after_include type in example config
* cargo update
* cfg: Remove another clippy warning.
* Fix `clippy::uninlined_format_args`
* Update toml to 0.9
* Release 0.29.0
* Support no-export annotation for statics and functions.
* conditional fields of constexpr literal structs
* Add LiteralStructField
* Github action: Add aarch64 to deploy
* Add rename rule for generated associated constant
* Upgrade heck to 0.5
* Add support for an optional nullable attribute
* docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes'
* Fix generic with 'void' default
* The return of Cast is simplified
* Added tests for as keyword inside array into structs
* Fixed error generation of structures using the keyword of as inside arrays
* Added test for unsafe(no_mangle) attribute
* Added tests for unsafe methotd's atributs
* Fixed handling of trait methods containing the unsafe attribute
* Rename -Zparse-only
* Release 0.28.0
* tests: Fix symbol file and tests.
* Appease clippy.
* tests: Run rustfmt.

Changes in mozilla-nspr:
- update to NSPR 4.39
* Improved error handling in PR_CreateThread on Windows
* Cleanup and Type-cast fixes for prtime
* Remove unused prstreams C++ wrapper from NSPR
* Memory poisoning and Arena redzone fixes
* Removed emacs/vim modelines and .cvsignore files
* Added .editorconfig
- update to version 4.38.2
* Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1
- update to version 4.38.1
* Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds.
- update to version 4.38
* Removed support for HPUX and _PR_POLL_WITH_SELECT
* Fixed a bug in pt_TCP_SendTo on macOS
* Ensure parameter passed to isalpha() is unsigned char
- update to version 4.37
* PR_GetUniqueIdentity asserts on the 32767th call
* error LNK2019: unresolved external symbol _InterlockedCompareExchange
* initclk deadline elapsed macOS
* Remove prwin.h (formerly known as prwin16.h)
* Use builtin atomic functions on RISC-V32/64
* PR_FormatTimeUSEnglish() doesn't support '%e' format specifier

Changes in MozillaFirefox-branding-SLE:

- use suse_version for SLE16 (bsc#1273243)
- chage version to 153
- Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112)

Changes in mozilla-nss:

- Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863)
- Fix upper bound to allow FIPS approval for P-521.
- Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698).
- Don't consider unapproved algorithms for TLS 1.3 in FIPS mode.
- Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262).
- Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698).
- Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263).
- Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772).
- Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773).
- Add zeroization for ML-KEM, ported from upstream (bsc#1272774).
- Add zeroization for ML-DSA (bsc#1272774).
- nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes.

- Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262).
- Apply jitter enablement unconditionally (bsc#1262701).

- update to NSS 3.125

* Set nssckbi version to 2.88.
* Add Cybertrust Japan SecureSign Root CA16.
* Remove Email Trust bit from TrustAsia Global Root CA G3 and G4.
* Remove Entrust Root Certification Authority.
* Remove SecureSign Root CA12.
* Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket.
* replace references to nss-dev/nss with mozilla/nss.
* limit recursion depth in CMS decoder.
* clamp input.len to testString size in pk11_mergeSecretKey.
* NULL pointer dereference in CERT_MergeExtensions.
* CERT_DecodeAVAValue Integer Overflow in Output Buffer Sizing.
* fix two integer overflows on LLP64 systems.
* Modify an assertion in ssl3_ClientSendAppProtoXtn.
* I ...

Please note that the description has been truncated due to length. Please refer to vendor advisory for the full description.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1226112

https://bugzilla.suse.com/1262698

https://bugzilla.suse.com/1262701

https://bugzilla.suse.com/1266262

https://bugzilla.suse.com/1266263

https://bugzilla.suse.com/1271649

https://bugzilla.suse.com/1272772

https://bugzilla.suse.com/1272773

https://bugzilla.suse.com/1272774

https://bugzilla.suse.com/1273243

https://bugzilla.suse.com/1274867

https://bugzilla.suse.com/1278001

https://bugzilla.suse.com/1279863

https://www.suse.com/security/cve/CVE-2026-16349

https://www.suse.com/security/cve/CVE-2026-16350

https://www.suse.com/security/cve/CVE-2026-16351

https://www.suse.com/security/cve/CVE-2026-16352

https://www.suse.com/security/cve/CVE-2026-16353

https://www.suse.com/security/cve/CVE-2026-16354

https://www.suse.com/security/cve/CVE-2026-16355

https://www.suse.com/security/cve/CVE-2026-16356

https://www.suse.com/security/cve/CVE-2026-16357

https://www.suse.com/security/cve/CVE-2026-16358

https://www.suse.com/security/cve/CVE-2026-16359

https://www.suse.com/security/cve/CVE-2026-16360

https://www.suse.com/security/cve/CVE-2026-16362

https://www.suse.com/security/cve/CVE-2026-16363

https://www.suse.com/security/cve/CVE-2026-16364

https://www.suse.com/security/cve/CVE-2026-16365

https://www.suse.com/security/cve/CVE-2026-16366

https://www.suse.com/security/cve/CVE-2026-16367

https://www.suse.com/security/cve/CVE-2026-16368

https://www.suse.com/security/cve/CVE-2026-16369

https://www.suse.com/security/cve/CVE-2026-16370

https://www.suse.com/security/cve/CVE-2026-16371

https://www.suse.com/security/cve/CVE-2026-16372

https://www.suse.com/security/cve/CVE-2026-16373

https://www.suse.com/security/cve/CVE-2026-16374

https://www.suse.com/security/cve/CVE-2026-16375

https://www.suse.com/security/cve/CVE-2026-16376

https://www.suse.com/security/cve/CVE-2026-16377

https://www.suse.com/security/cve/CVE-2026-16378

https://www.suse.com/security/cve/CVE-2026-16379

https://www.suse.com/security/cve/CVE-2026-16380

https://www.suse.com/security/cve/CVE-2026-16381

https://www.suse.com/security/cve/CVE-2026-16382

https://www.suse.com/security/cve/CVE-2026-16383

https://www.suse.com/security/cve/CVE-2026-16384

https://www.suse.com/security/cve/CVE-2026-16385

https://www.suse.com/security/cve/CVE-2026-16386

https://www.suse.com/security/cve/CVE-2026-16387

https://www.suse.com/security/cve/CVE-2026-16388

https://www.suse.com/security/cve/CVE-2026-16389

https://www.suse.com/security/cve/CVE-2026-16390

https://www.suse.com/security/cve/CVE-2026-16391

https://www.suse.com/security/cve/CVE-2026-16392

https://www.suse.com/security/cve/CVE-2026-16393

https://www.suse.com/security/cve/CVE-2026-16394

https://www.suse.com/security/cve/CVE-2026-16395

https://www.suse.com/security/cve/CVE-2026-16396

https://www.suse.com/security/cve/CVE-2026-16397

https://www.suse.com/security/cve/CVE-2026-16398

https://www.suse.com/security/cve/CVE-2026-16399

https://www.suse.com/security/cve/CVE-2026-16400

https://www.suse.com/security/cve/CVE-2026-16401

https://www.suse.com/security/cve/CVE-2026-16402

https://www.suse.com/security/cve/CVE-2026-16403

https://www.suse.com/security/cve/CVE-2026-16404

https://www.suse.com/security/cve/CVE-2026-16405

https://www.suse.com/security/cve/CVE-2026-16406

https://www.suse.com/security/cve/CVE-2026-16407

https://www.suse.com/security/cve/CVE-2026-16408

https://www.suse.com/security/cve/CVE-2026-16409

https://www.suse.com/security/cve/CVE-2026-16410

https://www.suse.com/security/cve/CVE-2026-16411

https://www.suse.com/security/cve/CVE-2026-16412

https://www.suse.com/security/cve/CVE-2026-74934

https://www.suse.com/security/cve/CVE-2026-74935

https://www.suse.com/security/cve/CVE-2026-74936

https://www.suse.com/security/cve/CVE-2026-74937

https://www.suse.com/security/cve/CVE-2026-74938

https://www.suse.com/security/cve/CVE-2026-74939

https://www.suse.com/security/cve/CVE-2026-74940

https://www.suse.com/security/cve/CVE-2026-74941

https://www.suse.com/security/cve/CVE-2026-74942

https://www.suse.com/security/cve/CVE-2026-74943

https://www.suse.com/security/cve/CVE-2026-74944

https://www.suse.com/security/cve/CVE-2026-74945

https://www.suse.com/security/cve/CVE-2026-74946

https://www.suse.com/security/cve/CVE-2026-74947

https://www.suse.com/security/cve/CVE-2026-74948

https://www.suse.com/security/cve/CVE-2026-74949

https://www.suse.com/security/cve/CVE-2026-74950

https://www.suse.com/security/cve/CVE-2026-74952

https://www.suse.com/security/cve/CVE-2026-74953

https://www.suse.com/security/cve/CVE-2026-74954

https://www.suse.com/security/cve/CVE-2026-74955

https://www.suse.com/security/cve/CVE-2026-74956

https://www.suse.com/security/cve/CVE-2026-74957

https://www.suse.com/security/cve/CVE-2026-74958

https://www.suse.com/security/cve/CVE-2026-74959

https://www.suse.com/security/cve/CVE-2026-74960

https://www.suse.com/security/cve/CVE-2026-74961

https://www.suse.com/security/cve/CVE-2026-74962

https://www.suse.com/security/cve/CVE-2026-74963

https://www.suse.com/security/cve/CVE-2026-74964

https://www.suse.com/security/cve/CVE-2026-74965

https://www.suse.com/security/cve/CVE-2026-74966

https://www.suse.com/security/cve/CVE-2026-74967

https://www.suse.com/security/cve/CVE-2026-74968

https://www.suse.com/security/cve/CVE-2026-74969

https://www.suse.com/security/cve/CVE-2026-74970

https://www.suse.com/security/cve/CVE-2026-74971

https://www.suse.com/security/cve/CVE-2026-74972

https://www.suse.com/security/cve/CVE-2026-74973

https://www.suse.com/security/cve/CVE-2026-74974

https://www.suse.com/security/cve/CVE-2026-74976

https://www.suse.com/security/cve/CVE-2026-74977

https://www.suse.com/security/cve/CVE-2026-74978

https://www.suse.com/security/cve/CVE-2026-74979

https://www.suse.com/security/cve/CVE-2026-74981

https://www.suse.com/security/cve/CVE-2026-74982

https://www.suse.com/security/cve/CVE-2026-74983

https://www.suse.com/security/cve/CVE-2026-74984

https://www.suse.com/security/cve/CVE-2026-74985

https://www.suse.com/security/cve/CVE-2026-74986

https://www.suse.com/security/cve/CVE-2026-74987

https://www.suse.com/security/cve/CVE-2026-74988

https://www.suse.com/security/cve/CVE-2026-74990

https://www.suse.com/security/cve/CVE-2026-75874

https://www.suse.com/security/cve/CVE-2026-84118

https://www.suse.com/security/cve/CVE-2026-84119

https://www.suse.com/security/cve/CVE-2026-84120

https://www.suse.com/security/cve/CVE-2026-84121

https://www.suse.com/security/cve/CVE-2026-84122

https://www.suse.com/security/cve/CVE-2026-84123

https://www.suse.com/security/cve/CVE-2026-84124

https://www.suse.com/security/cve/CVE-2026-84125

https://www.suse.com/security/cve/CVE-2026-84129

https://www.suse.com/security/cve/CVE-2026-84130

https://www.suse.com/security/cve/CVE-2026-84131

https://www.suse.com/security/cve/CVE-2026-84132

https://www.suse.com/security/cve/CVE-2026-84133

https://www.suse.com/security/cve/CVE-2026-84134

https://www.suse.com/security/cve/CVE-2026-84136

https://www.suse.com/security/cve/CVE-2026-84137

https://www.suse.com/security/cve/CVE-2026-84139

https://www.suse.com/security/cve/CVE-2026-84140

https://www.suse.com/security/cve/CVE-2026-84141

https://www.suse.com/security/cve/CVE-2026-84143

https://www.suse.com/security/cve/CVE-2026-84144

https://www.suse.com/security/cve/CVE-2026-84145

http://www.nessus.org/u?551fdd2f

Plugin Details

Severity: Critical

ID: 346212

File Name: suse_SU-2026-4156-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/16/2026

Updated: 9/16/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.35

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-84143

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:libfreebl3-32bit, p-cpe:/a:novell:suse_linux:libfreebl3, p-cpe:/a:novell:suse_linux:libsoftokn3-32bit, p-cpe:/a:novell:suse_linux:libsoftokn3, p-cpe:/a:novell:suse_linux:mozilla-nspr-32bit, p-cpe:/a:novell:suse_linux:mozilla-nspr-devel, p-cpe:/a:novell:suse_linux:mozilla-nspr, p-cpe:/a:novell:suse_linux:mozilla-nss-32bit, p-cpe:/a:novell:suse_linux:mozilla-nss-certs-32bit, p-cpe:/a:novell:suse_linux:mozilla-nss-certs, p-cpe:/a:novell:suse_linux:mozilla-nss-devel, p-cpe:/a:novell:suse_linux:mozilla-nss-sysinit, p-cpe:/a:novell:suse_linux:mozilla-nss-tools, p-cpe:/a:novell:suse_linux:mozilla-nss, p-cpe:/a:novell:suse_linux:mozillafirefox-branding-sle, p-cpe:/a:novell:suse_linux:mozillafirefox-devel, p-cpe:/a:novell:suse_linux:mozillafirefox-translations-common, p-cpe:/a:novell:suse_linux:mozillafirefox-translations-other, p-cpe:/a:novell:suse_linux:mozillafirefox

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/14/2026

Vulnerability Publication Date: 7/21/2026

Reference Information

CVE: CVE-2026-16349, CVE-2026-16350, CVE-2026-16351, CVE-2026-16352, CVE-2026-16353, CVE-2026-16354, CVE-2026-16355, CVE-2026-16356, CVE-2026-16357, CVE-2026-16358, CVE-2026-16359, CVE-2026-16360, CVE-2026-16362, CVE-2026-16363, CVE-2026-16364, CVE-2026-16365, CVE-2026-16366, CVE-2026-16367, CVE-2026-16368, CVE-2026-16369, CVE-2026-16370, CVE-2026-16371, CVE-2026-16372, CVE-2026-16373, CVE-2026-16374, CVE-2026-16375, CVE-2026-16376, CVE-2026-16377, CVE-2026-16378, CVE-2026-16379, CVE-2026-16380, CVE-2026-16381, CVE-2026-16382, CVE-2026-16383, CVE-2026-16384, CVE-2026-16385, CVE-2026-16386, CVE-2026-16387, CVE-2026-16388, CVE-2026-16389, CVE-2026-16390, CVE-2026-16391, CVE-2026-16392, CVE-2026-16393, CVE-2026-16394, CVE-2026-16395, CVE-2026-16396, CVE-2026-16397, CVE-2026-16398, CVE-2026-16399, CVE-2026-16400, CVE-2026-16401, CVE-2026-16402, CVE-2026-16403, CVE-2026-16404, CVE-2026-16405, CVE-2026-16406, CVE-2026-16407, CVE-2026-16408, CVE-2026-16409, CVE-2026-16410, CVE-2026-16411, CVE-2026-16412, CVE-2026-74934, CVE-2026-74935, CVE-2026-74936, CVE-2026-74937, CVE-2026-74938, CVE-2026-74939, CVE-2026-74940, CVE-2026-74941, CVE-2026-74942, CVE-2026-74943, CVE-2026-74944, CVE-2026-74945, CVE-2026-74946, CVE-2026-74947, CVE-2026-74948, CVE-2026-74949, CVE-2026-74950, CVE-2026-74952, CVE-2026-74953, CVE-2026-74954, CVE-2026-74955, CVE-2026-74956, CVE-2026-74957, CVE-2026-74958, CVE-2026-74959, CVE-2026-74960, CVE-2026-74961, CVE-2026-74962, CVE-2026-74963, CVE-2026-74964, CVE-2026-74965, CVE-2026-74966, CVE-2026-74967, CVE-2026-74968, CVE-2026-74969, CVE-2026-74970, CVE-2026-74971, CVE-2026-74972, CVE-2026-74973, CVE-2026-74974, CVE-2026-74976, CVE-2026-74977, CVE-2026-74978, CVE-2026-74979, CVE-2026-74981, CVE-2026-74982, CVE-2026-74983, CVE-2026-74984, CVE-2026-74985, CVE-2026-74986, CVE-2026-74987, CVE-2026-74988, CVE-2026-74990, CVE-2026-75874, CVE-2026-84118, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84123, CVE-2026-84124, CVE-2026-84125, CVE-2026-84129, CVE-2026-84130, CVE-2026-84131, CVE-2026-84132, CVE-2026-84133, CVE-2026-84134, CVE-2026-84136, CVE-2026-84137, CVE-2026-84139, CVE-2026-84140, CVE-2026-84141, CVE-2026-84143, CVE-2026-84144, CVE-2026-84145

SuSE: SUSE-SU-2026:4156-1