Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package firefox-esr for openSUSE:Factory 
checked in at 2026-09-29 18:01:28
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/firefox-esr (Old)
 and      /work/SRC/openSUSE:Factory/.firefox-esr.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "firefox-esr"

Tue Sep 29 18:01:28 2026 rev:44 rq:1381483 version:153.4.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/firefox-esr/MozillaFirefox.changes       
2026-09-16 17:45:35.046139627 +0200
+++ /work/SRC/openSUSE:Factory/.firefox-esr.new.383539/MozillaFirefox.changes   
2026-09-29 18:01:30.279515107 +0200
@@ -1,0 +2,149 @@
+Tue Sep 29 09:13:49 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 153.4.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 153.4.0
+  https://www.mozilla.org/security/advisories/mfsa2026-100
+  MFSA 2026-100 (boo#1282929)
+  * CVE-2026-100756 (bmo#2047721)
+    Incorrect boundary conditions in the Audio/Video: Playback
+    component
+  * CVE-2026-100757 (bmo#2049352)
+    Use-after-free in the Widget component
+  * CVE-2026-100758 (bmo#2049792)
+    Sandbox escape in the DOM: Navigation component
+  * CVE-2026-100759 (bmo#2054736)
+    Uninitialized memory in the Storage: Quota Manager component
+  * CVE-2026-100760 (bmo#2058017)
+    Sandbox escape in the Security: Process Sandboxing component
+  * CVE-2026-100762 (bmo#2059404)
+    Sandbox escape due to use-after-free in the DOM: Content
+    Processes component
+  * CVE-2026-100765 (bmo#2061399)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100766 (bmo#2061526)
+    Information disclosure in the Networking: JAR component
+  * CVE-2026-100767 (bmo#2063680)
+    Use-after-free in the Networking: Cache component
+  * CVE-2026-100769 (bmo#2067190)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100770 (bmo#2068322)
+    Sandbox escape due to use-after-free in the DOM: Content
+    Processes component
+  * CVE-2026-100771 (bmo#2068336)
+    Undefined behavior in the DOM: Streams component
+  * CVE-2026-100772 (bmo#2068340)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100773 (bmo#2068346)
+    Use-after-free in the Storage: IndexedDB component
+  * CVE-2026-100774 (bmo#2068351)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100775 (bmo#2068367)
+    Sandbox escape in the Graphics component
+  * CVE-2026-100776 (bmo#2068374)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100777 (bmo#2068375)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100778 (bmo#2068406)
+    Sandbox escape due to use-after-free in the DOM: Core & HTML
+    component
+  * CVE-2026-100779 (bmo#2068417)
+    Use-after-free in the XSLT component
+  * CVE-2026-100780 (bmo#2068422)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100781 (bmo#2068434)
+    Sandbox escape due to incorrect boundary conditions in the
+    Graphics: WebRender component
+  * CVE-2026-100782 (bmo#2068456)
+    Privilege escalation due to incorrect boundary conditions in
+    the Graphics component
+  * CVE-2026-100783 (bmo#2069804)
+    Uninitialized memory in the Audio/Video component
+  * CVE-2026-100784 (bmo#2070264)
+    Use-after-free in the Layout: Text and Fonts component
+  * CVE-2026-100785 (bmo#2071064)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100786 (bmo#2071067)
+    Sandbox escape due to use-after-free in the Graphics
+    component
+  * CVE-2026-100787 (bmo#2071068)
+    Sandbox escape in the XUL component
+  * CVE-2026-100788 (bmo#2072413)
+    Invalid pointer in the JavaScript: WebAssembly component
+  * CVE-2026-100789 (bmo#2072429)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100790 (bmo#2072432)
+    Use-after-free in the XSLT component
+  * CVE-2026-100791 (bmo#2072433)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100832 (bmo#2072467)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100792 (bmo#2073266)
+    JIT miscompilation in the JavaScript: WebAssembly component
+  * CVE-2026-100794 (bmo#2028871)
+    Sandbox escape due to incorrect boundary conditions in the
+    Internationalization component
+  * CVE-2026-96869 (bmo#2041248)
+    Information disclosure in the Networking component
+  * CVE-2026-100797 (bmo#2050542)
+    Privilege escalation due to use-after-free in the Graphics:
+    WebRender component
+  * CVE-2026-100798 (bmo#2055694)
+    Cryptography misuse in Storage: Quota Manager component
+  * CVE-2026-100800 (bmo#2056767)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-100801 (bmo#2057112)
+    Privilege escalation in the DLL Services component
+  * CVE-2026-100803 (bmo#2057988)
+    Same-origin policy bypass in the WebExtensions component
+  * CVE-2026-100806 (bmo#2060408)
+    Uninitialized memory in the Graphics: WebGPU component
+  * CVE-2026-100807 (bmo#2062740)
+    Privilege escalation in the DOM: Service Workers component
+  * CVE-2026-100808 (bmo#2063488)
+    Mitigation bypass in the DOM: Service Workers component
+  * CVE-2026-100809 (bmo#2063658)
+    Same-origin policy bypass in the DevTools component
+  * CVE-2026-100811 (bmo#2067973)
+    Sandbox escape due to use-after-free in the DOM: Core & HTML
+    component
+  * CVE-2026-100812 (bmo#2068335)
+    Denial-of-service in the Graphics component
+  * CVE-2026-100814 (bmo#2068385)
+    Incorrect boundary conditions in the JavaScript Engine: JIT
+    component
+  * CVE-2026-100815 (bmo#2068404)
+    Use-after-free in the CSS Parsing and Computation component
+  * CVE-2026-100816 (bmo#2068648)
+    Site isolation issue in the DOM: Networking component
+  * CVE-2026-100818 (bmo#2069399)
+    Sandbox escape due to use-after-free in the Widget: Gtk
+    component
+  * CVE-2026-100819 (bmo#2071069)
+    Sandbox escape due to incorrect boundary conditions in the
+    XPCOM component
+  * CVE-2026-100820 (bmo#2071645)
+    Privilege escalation in the Address Bar component
+  * CVE-2026-100821 (bmo#2071784)
+    Site isolation issue in the Panning and Zooming component
+  * CVE-2026-100822 (bmo#2051115)
+    Spoofing issue in the Networking: HTTP component
+  * CVE-2026-100824 (bmo#2054767)
+    Privilege escalation in the Places component
+  * CVE-2026-100825 (bmo#2057465)
+    Use-after-free in the JavaScript Engine: JIT component
+  * CVE-2026-100826 (bmo#2059222)
+    Denial-of-service in the Storage: StorageManager component
+  * CVE-2026-100828 (bmo#2066019)
+    Mitigation bypass in the Bookmarks & History component
+  * CVE-2026-100829 (bmo#2066321)
+    Mitigation bypass in the DOM: Security component
+  * CVE-2026-100830 (bmo#2066770)
+    Mitigation bypass in the DOM: Navigation component
+  * CVE-2026-100831 (bmo#2067172)
+    Use-after-free in the DOM: UI Events & Focus Handling
+    component
+- Rebase mozilla-pgo.patch
+
+-------------------------------------------------------------------
firefox-esr.changes: same change

Old:
----
  firefox-153.3.0esr.source.tar.xz
  firefox-153.3.0esr.source.tar.xz.asc
  l10n-153.3.0esr.tar.xz

New:
----
  firefox-153.4.0esr.source.tar.xz
  firefox-153.4.0esr.source.tar.xz.asc
  l10n-153.4.0esr.tar.xz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ firefox-esr.spec ++++++
--- /var/tmp/diff_new_pack.rxeBx2/_old  2026-09-29 18:02:45.947675108 +0200
+++ /var/tmp/diff_new_pack.rxeBx2/_new  2026-09-29 18:02:45.949675192 +0200
@@ -41,8 +41,8 @@
 # major 69
 # mainver %%major.99
 %define major          153
-%define mainver        %major.3.0
-%define orig_version   153.3.0
+%define mainver        %major.4.0
+%define orig_version   153.4.0
 %define orig_suffix    esr
 %define update_channel esr
 %define branding       1

++++++ MozillaFirefox.changes.txt ++++++
--- /var/tmp/diff_new_pack.rxeBx2/_old  2026-09-29 18:02:46.098681415 +0200
+++ /var/tmp/diff_new_pack.rxeBx2/_new  2026-09-29 18:02:46.108681832 +0200
@@ -1,4 +1,153 @@
 -------------------------------------------------------------------
+Tue Sep 29 09:13:49 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 153.4.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 153.4.0
+  https://www.mozilla.org/security/advisories/mfsa2026-100
+  MFSA 2026-100 (boo#1282929)
+  * CVE-2026-100756 (bmo#2047721)
+    Incorrect boundary conditions in the Audio/Video: Playback
+    component
+  * CVE-2026-100757 (bmo#2049352)
+    Use-after-free in the Widget component
+  * CVE-2026-100758 (bmo#2049792)
+    Sandbox escape in the DOM: Navigation component
+  * CVE-2026-100759 (bmo#2054736)
+    Uninitialized memory in the Storage: Quota Manager component
+  * CVE-2026-100760 (bmo#2058017)
+    Sandbox escape in the Security: Process Sandboxing component
+  * CVE-2026-100762 (bmo#2059404)
+    Sandbox escape due to use-after-free in the DOM: Content
+    Processes component
+  * CVE-2026-100765 (bmo#2061399)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100766 (bmo#2061526)
+    Information disclosure in the Networking: JAR component
+  * CVE-2026-100767 (bmo#2063680)
+    Use-after-free in the Networking: Cache component
+  * CVE-2026-100769 (bmo#2067190)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100770 (bmo#2068322)
+    Sandbox escape due to use-after-free in the DOM: Content
+    Processes component
+  * CVE-2026-100771 (bmo#2068336)
+    Undefined behavior in the DOM: Streams component
+  * CVE-2026-100772 (bmo#2068340)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100773 (bmo#2068346)
+    Use-after-free in the Storage: IndexedDB component
+  * CVE-2026-100774 (bmo#2068351)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100775 (bmo#2068367)
+    Sandbox escape in the Graphics component
+  * CVE-2026-100776 (bmo#2068374)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100777 (bmo#2068375)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100778 (bmo#2068406)
+    Sandbox escape due to use-after-free in the DOM: Core & HTML
+    component
+  * CVE-2026-100779 (bmo#2068417)
+    Use-after-free in the XSLT component
+  * CVE-2026-100780 (bmo#2068422)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100781 (bmo#2068434)
+    Sandbox escape due to incorrect boundary conditions in the
+    Graphics: WebRender component
+  * CVE-2026-100782 (bmo#2068456)
+    Privilege escalation due to incorrect boundary conditions in
+    the Graphics component
+  * CVE-2026-100783 (bmo#2069804)
+    Uninitialized memory in the Audio/Video component
+  * CVE-2026-100784 (bmo#2070264)
+    Use-after-free in the Layout: Text and Fonts component
+  * CVE-2026-100785 (bmo#2071064)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100786 (bmo#2071067)
+    Sandbox escape due to use-after-free in the Graphics
+    component
+  * CVE-2026-100787 (bmo#2071068)
+    Sandbox escape in the XUL component
+  * CVE-2026-100788 (bmo#2072413)
+    Invalid pointer in the JavaScript: WebAssembly component
+  * CVE-2026-100789 (bmo#2072429)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100790 (bmo#2072432)
+    Use-after-free in the XSLT component
+  * CVE-2026-100791 (bmo#2072433)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100832 (bmo#2072467)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100792 (bmo#2073266)
+    JIT miscompilation in the JavaScript: WebAssembly component
+  * CVE-2026-100794 (bmo#2028871)
+    Sandbox escape due to incorrect boundary conditions in the
+    Internationalization component
+  * CVE-2026-96869 (bmo#2041248)
+    Information disclosure in the Networking component
+  * CVE-2026-100797 (bmo#2050542)
+    Privilege escalation due to use-after-free in the Graphics:
+    WebRender component
+  * CVE-2026-100798 (bmo#2055694)
+    Cryptography misuse in Storage: Quota Manager component
+  * CVE-2026-100800 (bmo#2056767)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-100801 (bmo#2057112)
+    Privilege escalation in the DLL Services component
+  * CVE-2026-100803 (bmo#2057988)
+    Same-origin policy bypass in the WebExtensions component
+  * CVE-2026-100806 (bmo#2060408)
+    Uninitialized memory in the Graphics: WebGPU component
+  * CVE-2026-100807 (bmo#2062740)
+    Privilege escalation in the DOM: Service Workers component
+  * CVE-2026-100808 (bmo#2063488)
+    Mitigation bypass in the DOM: Service Workers component
+  * CVE-2026-100809 (bmo#2063658)
+    Same-origin policy bypass in the DevTools component
+  * CVE-2026-100811 (bmo#2067973)
+    Sandbox escape due to use-after-free in the DOM: Core & HTML
+    component
+  * CVE-2026-100812 (bmo#2068335)
+    Denial-of-service in the Graphics component
+  * CVE-2026-100814 (bmo#2068385)
+    Incorrect boundary conditions in the JavaScript Engine: JIT
+    component
+  * CVE-2026-100815 (bmo#2068404)
+    Use-after-free in the CSS Parsing and Computation component
+  * CVE-2026-100816 (bmo#2068648)
+    Site isolation issue in the DOM: Networking component
+  * CVE-2026-100818 (bmo#2069399)
+    Sandbox escape due to use-after-free in the Widget: Gtk
+    component
+  * CVE-2026-100819 (bmo#2071069)
+    Sandbox escape due to incorrect boundary conditions in the
+    XPCOM component
+  * CVE-2026-100820 (bmo#2071645)
+    Privilege escalation in the Address Bar component
+  * CVE-2026-100821 (bmo#2071784)
+    Site isolation issue in the Panning and Zooming component
+  * CVE-2026-100822 (bmo#2051115)
+    Spoofing issue in the Networking: HTTP component
+  * CVE-2026-100824 (bmo#2054767)
+    Privilege escalation in the Places component
+  * CVE-2026-100825 (bmo#2057465)
+    Use-after-free in the JavaScript Engine: JIT component
+  * CVE-2026-100826 (bmo#2059222)
+    Denial-of-service in the Storage: StorageManager component
+  * CVE-2026-100828 (bmo#2066019)
+    Mitigation bypass in the Bookmarks & History component
+  * CVE-2026-100829 (bmo#2066321)
+    Mitigation bypass in the DOM: Security component
+  * CVE-2026-100830 (bmo#2066770)
+    Mitigation bypass in the DOM: Navigation component
+  * CVE-2026-100831 (bmo#2067172)
+    Use-after-free in the DOM: UI Events & Focus Handling
+    component
+- Rebase mozilla-pgo.patch
+
+-------------------------------------------------------------------
 Tue Sep 15 12:37:39 UTC 2026 - Manfred Hollstein <[email protected]>
 
 - Firefox Extended Support Release 153.3.0 ESR

++++++ firefox-153.3.0esr.source.tar.xz -> firefox-153.4.0esr.source.tar.xz 
++++++
/work/SRC/openSUSE:Factory/firefox-esr/firefox-153.3.0esr.source.tar.xz 
/work/SRC/openSUSE:Factory/.firefox-esr.new.383539/firefox-153.4.0esr.source.tar.xz
 differ: char 15, line 1

++++++ firefox-esr.changes.txt ++++++
--- /var/tmp/diff_new_pack.rxeBx2/_old  2026-09-29 18:02:46.244687512 +0200
+++ /var/tmp/diff_new_pack.rxeBx2/_new  2026-09-29 18:02:46.249687721 +0200
@@ -1,4 +1,153 @@
 -------------------------------------------------------------------
+Tue Sep 29 09:13:49 UTC 2026 - Manfred Hollstein <[email protected]>
+
+- Firefox Extended Support Release 153.4.0 ESR
+  * Fixed: Various security fixes.
+- Mozilla Firefox ESR 153.4.0
+  https://www.mozilla.org/security/advisories/mfsa2026-100
+  MFSA 2026-100 (boo#1282929)
+  * CVE-2026-100756 (bmo#2047721)
+    Incorrect boundary conditions in the Audio/Video: Playback
+    component
+  * CVE-2026-100757 (bmo#2049352)
+    Use-after-free in the Widget component
+  * CVE-2026-100758 (bmo#2049792)
+    Sandbox escape in the DOM: Navigation component
+  * CVE-2026-100759 (bmo#2054736)
+    Uninitialized memory in the Storage: Quota Manager component
+  * CVE-2026-100760 (bmo#2058017)
+    Sandbox escape in the Security: Process Sandboxing component
+  * CVE-2026-100762 (bmo#2059404)
+    Sandbox escape due to use-after-free in the DOM: Content
+    Processes component
+  * CVE-2026-100765 (bmo#2061399)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100766 (bmo#2061526)
+    Information disclosure in the Networking: JAR component
+  * CVE-2026-100767 (bmo#2063680)
+    Use-after-free in the Networking: Cache component
+  * CVE-2026-100769 (bmo#2067190)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100770 (bmo#2068322)
+    Sandbox escape due to use-after-free in the DOM: Content
+    Processes component
+  * CVE-2026-100771 (bmo#2068336)
+    Undefined behavior in the DOM: Streams component
+  * CVE-2026-100772 (bmo#2068340)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100773 (bmo#2068346)
+    Use-after-free in the Storage: IndexedDB component
+  * CVE-2026-100774 (bmo#2068351)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100775 (bmo#2068367)
+    Sandbox escape in the Graphics component
+  * CVE-2026-100776 (bmo#2068374)
+    Use-after-free in the JavaScript: WebAssembly component
+  * CVE-2026-100777 (bmo#2068375)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100778 (bmo#2068406)
+    Sandbox escape due to use-after-free in the DOM: Core & HTML
+    component
+  * CVE-2026-100779 (bmo#2068417)
+    Use-after-free in the XSLT component
+  * CVE-2026-100780 (bmo#2068422)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100781 (bmo#2068434)
+    Sandbox escape due to incorrect boundary conditions in the
+    Graphics: WebRender component
+  * CVE-2026-100782 (bmo#2068456)
+    Privilege escalation due to incorrect boundary conditions in
+    the Graphics component
+  * CVE-2026-100783 (bmo#2069804)
+    Uninitialized memory in the Audio/Video component
+  * CVE-2026-100784 (bmo#2070264)
+    Use-after-free in the Layout: Text and Fonts component
+  * CVE-2026-100785 (bmo#2071064)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100786 (bmo#2071067)
+    Sandbox escape due to use-after-free in the Graphics
+    component
+  * CVE-2026-100787 (bmo#2071068)
+    Sandbox escape in the XUL component
+  * CVE-2026-100788 (bmo#2072413)
+    Invalid pointer in the JavaScript: WebAssembly component
+  * CVE-2026-100789 (bmo#2072429)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100790 (bmo#2072432)
+    Use-after-free in the XSLT component
+  * CVE-2026-100791 (bmo#2072433)
+    Use-after-free in the DOM: Core & HTML component
+  * CVE-2026-100832 (bmo#2072467)
+    Use-after-free in the Graphics: Canvas2D component
+  * CVE-2026-100792 (bmo#2073266)
+    JIT miscompilation in the JavaScript: WebAssembly component
+  * CVE-2026-100794 (bmo#2028871)
+    Sandbox escape due to incorrect boundary conditions in the
+    Internationalization component
+  * CVE-2026-96869 (bmo#2041248)
+    Information disclosure in the Networking component
+  * CVE-2026-100797 (bmo#2050542)
+    Privilege escalation due to use-after-free in the Graphics:
+    WebRender component
+  * CVE-2026-100798 (bmo#2055694)
+    Cryptography misuse in Storage: Quota Manager component
+  * CVE-2026-100800 (bmo#2056767)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-100801 (bmo#2057112)
+    Privilege escalation in the DLL Services component
+  * CVE-2026-100803 (bmo#2057988)
+    Same-origin policy bypass in the WebExtensions component
+  * CVE-2026-100806 (bmo#2060408)
+    Uninitialized memory in the Graphics: WebGPU component
+  * CVE-2026-100807 (bmo#2062740)
+    Privilege escalation in the DOM: Service Workers component
+  * CVE-2026-100808 (bmo#2063488)
+    Mitigation bypass in the DOM: Service Workers component
+  * CVE-2026-100809 (bmo#2063658)
+    Same-origin policy bypass in the DevTools component
+  * CVE-2026-100811 (bmo#2067973)
+    Sandbox escape due to use-after-free in the DOM: Core & HTML
+    component
+  * CVE-2026-100812 (bmo#2068335)
+    Denial-of-service in the Graphics component
+  * CVE-2026-100814 (bmo#2068385)
+    Incorrect boundary conditions in the JavaScript Engine: JIT
+    component
+  * CVE-2026-100815 (bmo#2068404)
+    Use-after-free in the CSS Parsing and Computation component
+  * CVE-2026-100816 (bmo#2068648)
+    Site isolation issue in the DOM: Networking component
+  * CVE-2026-100818 (bmo#2069399)
+    Sandbox escape due to use-after-free in the Widget: Gtk
+    component
+  * CVE-2026-100819 (bmo#2071069)
+    Sandbox escape due to incorrect boundary conditions in the
+    XPCOM component
+  * CVE-2026-100820 (bmo#2071645)
+    Privilege escalation in the Address Bar component
+  * CVE-2026-100821 (bmo#2071784)
+    Site isolation issue in the Panning and Zooming component
+  * CVE-2026-100822 (bmo#2051115)
+    Spoofing issue in the Networking: HTTP component
+  * CVE-2026-100824 (bmo#2054767)
+    Privilege escalation in the Places component
+  * CVE-2026-100825 (bmo#2057465)
+    Use-after-free in the JavaScript Engine: JIT component
+  * CVE-2026-100826 (bmo#2059222)
+    Denial-of-service in the Storage: StorageManager component
+  * CVE-2026-100828 (bmo#2066019)
+    Mitigation bypass in the Bookmarks & History component
+  * CVE-2026-100829 (bmo#2066321)
+    Mitigation bypass in the DOM: Security component
+  * CVE-2026-100830 (bmo#2066770)
+    Mitigation bypass in the DOM: Navigation component
+  * CVE-2026-100831 (bmo#2067172)
+    Use-after-free in the DOM: UI Events & Focus Handling
+    component
+- Rebase mozilla-pgo.patch
+
+-------------------------------------------------------------------
 Tue Sep 15 12:37:39 UTC 2026 - Manfred Hollstein <[email protected]>
 
 - Firefox Extended Support Release 153.3.0 ESR

++++++ l10n-153.3.0esr.tar.xz -> l10n-153.4.0esr.tar.xz ++++++
/work/SRC/openSUSE:Factory/firefox-esr/l10n-153.3.0esr.tar.xz 
/work/SRC/openSUSE:Factory/.firefox-esr.new.383539/l10n-153.4.0esr.tar.xz 
differ: char 15, line 1

++++++ mozilla-pgo.patch ++++++
--- /var/tmp/diff_new_pack.rxeBx2/_old  2026-09-29 18:02:46.426695113 +0200
+++ /var/tmp/diff_new_pack.rxeBx2/_new  2026-09-29 18:02:46.429695238 +0200
@@ -1,6 +1,7 @@
 # HG changeset patch
 # User Wolfgang Rosenauer <[email protected]>
 # Parent  73147e14b378957cdb8516125df34111d2699fe9
+# Rebased by Manfred Hollstein <[email protected]>
 
 Index: mozilla-esr153/build/moz.configure/lto-pgo.configure
 ===================================================================
@@ -137,7 +138,7 @@
 ===================================================================
 --- mozilla-esr153.orig/toolkit/components/terminator/nsTerminator.cpp
 +++ mozilla-esr153/toolkit/components/terminator/nsTerminator.cpp
-@@ -392,6 +392,11 @@ void nsTerminator::StartWatchdog() {
+@@ -382,6 +382,11 @@ void nsTerminator::StartWatchdog() {
    }
  #endif
  
@@ -146,7 +147,7 @@
 +  // silently produce poorly performing binary.
 +  crashAfterMS = INT32_MAX;
 +
-   UniquePtr<Options> options(new Options());
-   // Guarantee that crashAfterTicks is non-zero
-   options->crashAfterTicks = std::max(1, crashAfterMS / 
HEARTBEAT_INTERVAL_MS);
+   // Guarantee that gCrashAfterTicks is non-zero
+   gCrashAfterTicks = std::max(1, crashAfterMS / HEARTBEAT_INTERVAL_MS);
+ 
 

++++++ tar_stamps ++++++
--- /var/tmp/diff_new_pack.rxeBx2/_old  2026-09-29 18:02:46.522699122 +0200
+++ /var/tmp/diff_new_pack.rxeBx2/_new  2026-09-29 18:02:46.526699289 +0200
@@ -1,11 +1,11 @@
 PRODUCT="firefox"
 CHANNEL="esr153"
-VERSION="153.3.0"
+VERSION="153.4.0"
 VERSION_SUFFIX="esr"
-PREV_VERSION="153.2.0"
+PREV_VERSION="153.3.0"
 PREV_VERSION_SUFFIX="esr"
 #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
 RELEASE_REPO="https://hg.mozilla.org/releases/mozilla-esr153";
-RELEASE_TAG="3b49a44994fb7ff6902f7df5a3bd5f689a4fb4e9"
-RELEASE_TIMESTAMP="20260908150240"
+RELEASE_TAG="ec9c1cc8a5cb6fac9d4d17e4f141fb42a8089b4c"
+RELEASE_TIMESTAMP="20260923073912"
 

Reply via email to