Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package MozillaFirefox for openSUSE:Factory
checked in at 2026-09-21 12:00:13
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/MozillaFirefox (Old)
and /work/SRC/openSUSE:Factory/.MozillaFirefox.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "MozillaFirefox"
Mon Sep 21 12:00:13 2026 rev:502 rq:1379127 version:156.0
Changes:
--------
--- /work/SRC/openSUSE:Factory/MozillaFirefox/MozillaFirefox.changes
2026-09-08 16:51:50.199227162 +0200
+++
/work/SRC/openSUSE:Factory/.MozillaFirefox.new.383539/MozillaFirefox.changes
2026-09-21 12:00:18.939932951 +0200
@@ -1,0 +2,174 @@
+Thu Sep 17 05:37:31 UTC 2026 - Wolfgang Rosenauer <[email protected]>
+
+- Mozilla Firefox 156.0
+ https://www.firefox.com/en-US/firefox/156.0/releasenotes/
+ MFSA 2026-90 (bsc#1280371)
+ * CVE-2026-92033 (bmo#2047339)
+ Privilege escalation in Firefox for Android
+ * CVE-2026-92005 (bmo#2056051)
+ Use-after-free in the Audio/Video: Web Codecs component
+ * CVE-2026-92006 (bmo#2057121)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92007 (bmo#2058064)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92008 (bmo#2058065)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92009 (bmo#2058066)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92010 (bmo#2058067)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92011 (bmo#2058068)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92012 (bmo#2058069)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92013 (bmo#2058078)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92015 (bmo#2060235)
+ Privilege escalation in the WebExtensions component
+ * CVE-2026-92034 (bmo#2060295)
+ Site isolation issue in the Graphics component
+ * CVE-2026-92035 (bmo#2061245)
+ Sandbox escape due to incorrect boundary conditions in the
+ Graphics component
+ * CVE-2026-92016 (bmo#2061327)
+ Use-after-free in the Disability Access APIs component
+ * CVE-2026-92017 (bmo#2061777)
+ Privilege escalation in the DOM: Service Workers component
+ * CVE-2026-92018 (bmo#2064287)
+ Sandbox escape in the DOM: Core & HTML component
+ * CVE-2026-92019 (bmo#2065636)
+ Mitigation bypass in the Remote Settings Client component
+ * CVE-2026-92020 (bmo#2066329)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: WebRender component
+ * CVE-2026-92022 (bmo#2068059)
+ Use-after-free in the DOM: HTML Parser component
+ * CVE-2026-92023 (bmo#2068342)
+ Use-after-free in the XML component
+ * CVE-2026-92024 (bmo#2068354)
+ Use-after-free in the SVG component
+ * CVE-2026-92025 (bmo#2068361)
+ Use-after-free in the DOM: Navigation component
+ * CVE-2026-92026 (bmo#2068378)
+ Use-after-free in the Networking component
+ * CVE-2026-92036 (bmo#2068416)
+ Incorrect boundary conditions in the Networking: HTTP component
+ * CVE-2026-92027 (bmo#2068433)
+ Use-after-free in the DOM: Streams component
+ * CVE-2026-92028 (bmo#2068440)
+ Use-after-free in the DOM: Core & HTML component
+ * CVE-2026-92029 (bmo#2068445)
+ Use-after-free in the SVG component
+ * CVE-2026-92037 (bmo#2068460)
+ Incorrect boundary conditions in the DOM: Animation component
+ * CVE-2026-92038 (bmo#2068952)
+ Mitigation bypass in the Remote Settings Client component
+ * CVE-2026-92039 (bmo#2001265)
+ Mitigation bypass in the DOM: Notifications component
+ * CVE-2026-92040 (bmo#2024248)
+ Use-after-free in the JavaScript: WebAssembly component
+ * CVE-2026-92041 (bmo#2029482)
+ Mitigation bypass in the DOM: Networking component
+ * CVE-2026-92042 (bmo#2049342)
+ Race condition in the DOM: Content Processes component
+ * CVE-2026-92043 (bmo#2050150)
+ Privilege escalation due to incorrect boundary conditions in
+ the Audio/Video component
+ * CVE-2026-92044 (bmo#2051466)
+ Information disclosure in the Networking: HTTP component
+ * CVE-2026-92045 (bmo#2054622)
+ Sandbox escape due to incorrect boundary conditions in the
+ WebRTC component
+ * CVE-2026-92030 (bmo#2058417)
+ Mitigation bypass in the DOM: Copy & Paste and Drag & Drop
+ component
+ * CVE-2026-92046 (bmo#2058618)
+ Use-after-free in the Graphics component
+ * CVE-2026-92047 (bmo#2059021)
+ Privilege escalation in the Crash Reporting component
+ * CVE-2026-92048 (bmo#2061235)
+ Sandbox escape due to incorrect boundary conditions in the
+ Widget: Win32 component
+ * CVE-2026-92049 (bmo#2061295)
+ Use-after-free in the Widget: Win32 component
+ * CVE-2026-92050 (bmo#2061387)
+ Sandbox escape due to race condition in the XPConnect component
+ * CVE-2026-92051 (bmo#2061393)
+ Spoofing issue due to invalid pointer in the Graphics component
+ * CVE-2026-92052 (bmo#2061499)
+ Privilege escalation due to uninitialized memory in the
+ Graphics: CanvasWebGL component
+ * CVE-2026-92053 (bmo#2061503)
+ Privilege escalation in the Graphics: CanvasWebGL component
+ * CVE-2026-92054 (bmo#2062551)
+ Privilege escalation in the Memory component
+ * CVE-2026-92055 (bmo#2063652)
+ Privilege escalation in the DevTools component
+ * CVE-2026-92056 (bmo#2065346)
+ Use-after-free in the Graphics: Text component
+ * CVE-2026-92057 (bmo#2065646)
+ Mitigation bypass in the Enterprise Policies component
+ * CVE-2026-92031 (bmo#2067971)
+ Information disclosure in the Graphics: ImageLib component
+ * CVE-2026-92032 (bmo#2068437)
+ Sandbox escape due to invalid pointer in the Graphics
+ component
+ * CVE-2026-92058 (bmo#2068438)
+ Use-after-free in the Graphics component
+ * CVE-2026-92059 (bmo#2068442)
+ Incorrect boundary conditions in the DOM: Editor component
+ * CVE-2026-92060 (bmo#2027336)
+ Use-after-free in the Internationalization component
+ * CVE-2026-92061 (bmo#2041758)
+ Incorrect boundary conditions in the Security: Process
+ Sandboxing component
+ * CVE-2026-92062 (bmo#2054670)
+ Privilege escalation in the Session Restore component
+ * CVE-2026-92063 (bmo#2055737)
+ Denial-of-service in the Audio/Video component
+ * CVE-2026-92064 (bmo#2057990)
+ Sandbox escape due to incorrect boundary conditions in the
+ Widget: Win32 component
+ * CVE-2026-92065 (bmo#2058018)
+ Sandbox escape due to incorrect boundary conditions in the
+ Widget: Win32 component
+ * CVE-2026-92066 (bmo#2058093)
+ Sandbox escape in the Profile Backup component
+ * CVE-2026-92067 (bmo#2058664)
+ Use-after-free in the Widget: Gtk component
+ * CVE-2026-92068 (bmo#2058790)
+ Site isolation issue in the Reader Mode component
+ * CVE-2026-92069 (bmo#2059196)
+ Spoofing issue in the DOM: Navigation component
+ * CVE-2026-92070 (bmo#2060220)
+ Information disclosure in the Networking component
+ * CVE-2026-92071 (bmo#2061231)
+ Sandbox escape due to incorrect boundary conditions in the
+ Widget: Win32 component
+ * CVE-2026-92072 (bmo#2061257)
+ Incorrect boundary conditions in the Safe Browsing component
+ * CVE-2026-92073 (bmo#2062527)
+ Privilege escalation in the Enterprise Policies component
+ * CVE-2026-92074 (bmo#2063539)
+ Mitigation bypass in the Popup Blocker component
+ * CVE-2026-92075 (bmo#2063814)
+ Mitigation bypass in the Networking component
+ * CVE-2026-92076 (bmo#2064026)
+ Incorrect boundary conditions in the Networking component
+ * CVE-2026-92077 (bmo#2064601)
+ Denial-of-service in the SVG component
+ * CVE-2026-92078 (bmo#2066736)
+ Denial-of-service in the Security component
+ * CVE-2026-92079 (bmo#2067531)
+ Mitigation bypass in the Widget: Win32 component
+- requires NSS 3.128
+
+-------------------------------------------------------------------
Old:
----
firefox-155.0.1.source.tar.xz
firefox-155.0.1.source.tar.xz.asc
l10n-155.0.1.tar.xz
New:
----
firefox-156.0.source.tar.xz
firefox-156.0.source.tar.xz.asc
l10n-156.0.tar.xz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ MozillaFirefox.spec ++++++
--- /var/tmp/diff_new_pack.gtu7J6/_old 2026-09-21 12:01:04.729853364 +0200
+++ /var/tmp/diff_new_pack.gtu7J6/_new 2026-09-21 12:01:04.733853532 +0200
@@ -28,9 +28,9 @@
# orig_suffix b3
# major 69
# mainver %%major.99
-%define major 155
-%define mainver %major.0.1
-%define orig_version 155.0.1
+%define major 156
+%define mainver %major.0
+%define orig_version 156.0
%define orig_suffix %{nil}
%define update_channel release
%define branding 1
@@ -130,7 +130,7 @@
BuildRequires: libproxy-devel
BuildRequires: makeinfo
BuildRequires: mozilla-nspr-devel >= 4.40
-BuildRequires: mozilla-nss-devel >= 3.127
+BuildRequires: mozilla-nss-devel >= 3.128
BuildRequires: nasm >= 2.14
BuildRequires: nodejs >= 12.22.12
%if 0%{?sle_version} >= 120000 && 0%{?sle_version} < 150000
++++++ firefox-155.0.1.source.tar.xz -> firefox-156.0.source.tar.xz ++++++
/work/SRC/openSUSE:Factory/MozillaFirefox/firefox-155.0.1.source.tar.xz
/work/SRC/openSUSE:Factory/.MozillaFirefox.new.383539/firefox-156.0.source.tar.xz
differ: char 15, line 1
++++++ l10n-155.0.1.tar.xz -> l10n-156.0.tar.xz ++++++
/work/SRC/openSUSE:Factory/MozillaFirefox/l10n-155.0.1.tar.xz
/work/SRC/openSUSE:Factory/.MozillaFirefox.new.383539/l10n-156.0.tar.xz differ:
char 15, line 1
++++++ tar_stamps ++++++
--- /var/tmp/diff_new_pack.gtu7J6/_old 2026-09-21 12:01:05.090868505 +0200
+++ /var/tmp/diff_new_pack.gtu7J6/_new 2026-09-21 12:01:05.093868631 +0200
@@ -1,11 +1,11 @@
PRODUCT="firefox"
CHANNEL="release"
-VERSION="155.0.1"
+VERSION="156.0"
VERSION_SUFFIX=""
-PREV_VERSION="155.0"
+PREV_VERSION="155.0.1"
PREV_VERSION_SUFFIX=""
#SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
RELEASE_REPO="https://hg.mozilla.org/releases/mozilla-release"
-RELEASE_TAG="5fdfd0092780e85643e2cddc0e1b590c8b9ef860"
-RELEASE_TIMESTAMP="20260903215306"
+RELEASE_TAG="a80bd15ddee3b4bf3679aeba340e9d2db933c467"
+RELEASE_TIMESTAMP="20260909172920"