Description of the patch:
This update for MozillaFirefox fixes the following issues:
Firefox Extended Support Release 140.13.0 ESR (MFSA 2026-70, bsc#1271649):
CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component.
CVE-2026-15719: Site isolation issue in the DOM: Navigation component.
CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component.
CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component.
CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component.
CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component.
CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component.
CVE-2026-16354: Information disclosure in the Graphics: ImageLib component.
CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component.
CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component.
CVE-2026-16357: Incorrect boundary conditions in the Graphics component.
CVE-2026-16358: Site isolation issue in the Graphics: WebRender component.
CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component.
CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153.
CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13.
CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component.
CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component.
CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component.
CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component.
CVE-2026-16371: Privilege escalation in the DOM: Navigation component.
CVE-2026-16374: Information disclosure in the Framework component in DevTools.
CVE-2026-16375: Site isolation issue in the Networking: HTTP component.
CVE-2026-16377: Mitigation bypass in...
140.13.0-112.324.2140.13.0-112.324.2140.13.0-112.324.2