openSUSE 16: MozillaFirefox / MozillaFirefox-branding-upstream / etc (openSUSE-SU-2026:21980-1)

critical Nessus Plugin ID 362524

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21980-1 advisory.

Update to Firefox Extended Support Release 153.4.0 ESR (MFSA 2026-100, bsc#1282929):

- CVE-2026-96869: Information disclosure in the Networking component.
- CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component.
- CVE-2026-100757: Use-after-free in the Widget component.
- CVE-2026-100758: Sandbox escape in the DOM: Navigation component.
- CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager component.
- CVE-2026-100760: Sandbox escape in the Security: Process Sandboxing component.
- CVE-2026-100762: Sandbox escape due to use-after-free in the DOM: Content Processes component.
- CVE-2026-100765: Use-after-free in the JavaScript: WebAssembly component.
- CVE-2026-100766: Information disclosure in the Networking: JAR component.
- CVE-2026-100767: Use-after-free in the Networking: Cache component.
- CVE-2026-100769: Use-after-free in the JavaScript: WebAssembly component.
- CVE-2026-100770: Sandbox escape due to use-after-free in the DOM: Content Processes component.
- CVE-2026-100771: Undefined behavior in the DOM: Streams component.
- CVE-2026-100772: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-100773: Use-after-free in the Storage: IndexedDB component.
- CVE-2026-100774: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-100775: Sandbox escape in the Graphics component.
- CVE-2026-100776: Use-after-free in the JavaScript: WebAssembly component.
- CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component.
- CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core & HTML component.
- CVE-2026-100779: Use-after-free in the XSLT component.
- CVE-2026-100780: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-100781: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component.
- CVE-2026-100782: Privilege escalation due to incorrect boundary conditions in the Graphics component.
- CVE-2026-100783: Uninitialized memory in the Audio/Video component.
- CVE-2026-100784: Use-after-free in the Layout: Text and Fonts component.
- CVE-2026-100785: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics component.
- CVE-2026-100787: Sandbox escape in the XUL component.
- CVE-2026-100788: Invalid pointer in the JavaScript: WebAssembly component.
- CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component.
- CVE-2026-100790: Use-after-free in the XSLT component.
- CVE-2026-100791: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-100792: JIT miscompilation in the JavaScript: WebAssembly component.
- CVE-2026-100794: Sandbox escape due to incorrect boundary conditions in the Internationalization component.
- CVE-2026-100797: Privilege escalation due to use-after-free in the Graphics: WebRender component.
- CVE-2026-100798: Cryptography misuse in Storage: Quota Manager component.
- CVE-2026-100800: Sandbox escape due to use-after-free in the Disability Access APIs component.
- CVE-2026-100801: Privilege escalation in the DLL Services component.
- CVE-2026-100803: Same-origin policy bypass in the WebExtensions component.
- CVE-2026-100806: Uninitialized memory in the Graphics: WebGPU component.
- CVE-2026-100807: Privilege escalation in the DOM: Service Workers component.
- CVE-2026-100808: Mitigation bypass in the DOM: Service Workers component.
- CVE-2026-100809: Same-origin policy bypass in the DevTools component.
- CVE-2026-100811: Sandbox escape due to use-after-free in the DOM: Core & HTML component.
- CVE-2026-100812: Denial-of-service in the Graphics component.
- CVE-2026-100814: Incorrect boundary conditions in the JavaScript Engine: JIT component.
- CVE-2026-100815: Use-after-free in the CSS Parsing and Computation component.
- CVE-2026-100816: Site isolation issue in the DOM: Networking component.
- CVE-2026-100818: Sandbox escape due to use-after-free in the Widget: Gtk component.
- CVE-2026-100819: Sandbox escape due to incorrect boundary conditions in the XPCOM component.
- CVE-2026-100820: Privilege escalation in the Address Bar component.
- CVE-2026-100821: Site isolation issue in the Panning and Zooming component.
- CVE-2026-100822: Spoofing issue in the Networking: HTTP component.
- CVE-2026-100824: Privilege escalation in the Places component.
- CVE-2026-100825: Use-after-free in the JavaScript Engine: JIT component.
- CVE-2026-100826: Denial-of-service in the Storage: StorageManager component.
- CVE-2026-100828: Mitigation bypass in the Bookmarks & History component.
- CVE-2026-100829: Mitigation bypass in the DOM: Security component.
- CVE-2026-100830: Mitigation bypass in the DOM: Navigation component.
- CVE-2026-100831: Use-after-free in the DOM: UI Events & Focus Handling component.
- CVE-2026-100832: Use-after-free in the Graphics: Canvas2D component.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1282929

https://www.suse.com/security/cve/CVE-2026-100756

https://www.suse.com/security/cve/CVE-2026-100757

https://www.suse.com/security/cve/CVE-2026-100758

https://www.suse.com/security/cve/CVE-2026-100759

https://www.suse.com/security/cve/CVE-2026-100760

https://www.suse.com/security/cve/CVE-2026-100762

https://www.suse.com/security/cve/CVE-2026-100765

https://www.suse.com/security/cve/CVE-2026-100766

https://www.suse.com/security/cve/CVE-2026-100767

https://www.suse.com/security/cve/CVE-2026-100769

https://www.suse.com/security/cve/CVE-2026-100770

https://www.suse.com/security/cve/CVE-2026-100771

https://www.suse.com/security/cve/CVE-2026-100772

https://www.suse.com/security/cve/CVE-2026-100773

https://www.suse.com/security/cve/CVE-2026-100774

https://www.suse.com/security/cve/CVE-2026-100775

https://www.suse.com/security/cve/CVE-2026-100776

https://www.suse.com/security/cve/CVE-2026-100777

https://www.suse.com/security/cve/CVE-2026-100778

https://www.suse.com/security/cve/CVE-2026-100779

https://www.suse.com/security/cve/CVE-2026-100780

https://www.suse.com/security/cve/CVE-2026-100781

https://www.suse.com/security/cve/CVE-2026-100782

https://www.suse.com/security/cve/CVE-2026-100783

https://www.suse.com/security/cve/CVE-2026-100784

https://www.suse.com/security/cve/CVE-2026-100785

https://www.suse.com/security/cve/CVE-2026-100786

https://www.suse.com/security/cve/CVE-2026-100787

https://www.suse.com/security/cve/CVE-2026-100788

https://www.suse.com/security/cve/CVE-2026-100789

https://www.suse.com/security/cve/CVE-2026-100790

https://www.suse.com/security/cve/CVE-2026-100791

https://www.suse.com/security/cve/CVE-2026-100792

https://www.suse.com/security/cve/CVE-2026-100794

https://www.suse.com/security/cve/CVE-2026-100797

https://www.suse.com/security/cve/CVE-2026-100798

https://www.suse.com/security/cve/CVE-2026-100800

https://www.suse.com/security/cve/CVE-2026-100801

https://www.suse.com/security/cve/CVE-2026-100803

https://www.suse.com/security/cve/CVE-2026-100806

https://www.suse.com/security/cve/CVE-2026-100807

https://www.suse.com/security/cve/CVE-2026-100808

https://www.suse.com/security/cve/CVE-2026-100809

https://www.suse.com/security/cve/CVE-2026-100811

https://www.suse.com/security/cve/CVE-2026-100812

https://www.suse.com/security/cve/CVE-2026-100814

https://www.suse.com/security/cve/CVE-2026-100815

https://www.suse.com/security/cve/CVE-2026-100816

https://www.suse.com/security/cve/CVE-2026-100818

https://www.suse.com/security/cve/CVE-2026-100819

https://www.suse.com/security/cve/CVE-2026-100820

https://www.suse.com/security/cve/CVE-2026-100821

https://www.suse.com/security/cve/CVE-2026-100822

https://www.suse.com/security/cve/CVE-2026-100824

https://www.suse.com/security/cve/CVE-2026-100825

https://www.suse.com/security/cve/CVE-2026-100826

https://www.suse.com/security/cve/CVE-2026-100828

https://www.suse.com/security/cve/CVE-2026-100829

https://www.suse.com/security/cve/CVE-2026-100830

https://www.suse.com/security/cve/CVE-2026-100831

https://www.suse.com/security/cve/CVE-2026-100832

https://www.suse.com/security/cve/CVE-2026-96869

Plugin Details

Severity: Critical

ID: 362524

File Name: openSUSE-2026-21980-1.nasl

Version: 1.2

Type: Local

Agent: unix

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.18

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-100832

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-100788

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:mozillafirefox-branding-upstream, p-cpe:/a:novell:opensuse:mozillafirefox-devel, p-cpe:/a:novell:opensuse:mozillafirefox-translations-common, p-cpe:/a:novell:opensuse:mozillafirefox-translations-other, p-cpe:/a:novell:opensuse:mozillafirefox

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-100756, CVE-2026-100757, CVE-2026-100758, CVE-2026-100759, CVE-2026-100760, CVE-2026-100762, CVE-2026-100765, CVE-2026-100766, CVE-2026-100767, CVE-2026-100769, CVE-2026-100770, CVE-2026-100771, CVE-2026-100772, CVE-2026-100773, CVE-2026-100774, CVE-2026-100775, CVE-2026-100776, CVE-2026-100777, CVE-2026-100778, CVE-2026-100779, CVE-2026-100780, CVE-2026-100781, CVE-2026-100782, CVE-2026-100783, CVE-2026-100784, CVE-2026-100785, CVE-2026-100786, CVE-2026-100787, CVE-2026-100788, CVE-2026-100789, CVE-2026-100790, CVE-2026-100791, CVE-2026-100792, CVE-2026-100794, CVE-2026-100797, CVE-2026-100798, CVE-2026-100800, CVE-2026-100801, CVE-2026-100803, CVE-2026-100806, CVE-2026-100807, CVE-2026-100808, CVE-2026-100809, CVE-2026-100811, CVE-2026-100812, CVE-2026-100814, CVE-2026-100815, CVE-2026-100816, CVE-2026-100818, CVE-2026-100819, CVE-2026-100820, CVE-2026-100821, CVE-2026-100822, CVE-2026-100824, CVE-2026-100825, CVE-2026-100826, CVE-2026-100828, CVE-2026-100829, CVE-2026-100830, CVE-2026-100831, CVE-2026-100832, CVE-2026-96869

IAVA: 2026-A-1076