openSUSE 16: MozillaFirefox / MozillaFirefox-branding-upstream / etc (openSUSE-SU-2026:21980-1)

critical Nessus プラグイン ID 362524

Language:

概要

リモートの openSUSE ホストに 1 つ以上のセキュリティアップデートがありません。

説明

リモートの openSUSE 16 ホストに、複数の脆弱性の影響を受けているパッケージがインストールされています。これらの脆弱性は openSUSE-SU-2026:21980-1 アドバイザリで言及されています。

Firefox 延長サポート版 153.4.0 ESR (MFSA 2026-100、bsc#1282929) に更新します:

- CVE-2026-96869:Networking コンポーネントの情報漏洩。
- CVE-2026-100756: Audio/Video: Playback コンポーネントの不適切な境界条件。
- CVE-2026-100757:Widget コンポーネントの use-after-free。
- CVE-2026-100758: DOM: Navigation コンポーネントのサンドボックスエスケープ。
- CVE-2026-100759:Storage: Quota Manager コンポーネントの初期化されていないメモリ。
- CVE-2026-100760: Security: Process Sandboxing コンポーネントのサンドボックスエスケープ。
- CVE-2026-100762:DOM の use-after-free によるサンドボックスのエスケープ:コンテンツプロセスコンポーネント。
- CVE-2026-100765: JavaScript: WebAssembly コンポーネントのメモリ解放後使用 (Use After Free)。
- CVE-2026-100766:Networking: JAR コンポーネントの情報漏洩。
- CVE-2026-100767:Networking: Cache コンポーネントでの use-after-free。
- CVE-2026-100769: JavaScript: WebAssembly コンポーネントのメモリ解放後使用 (Use After Free)。
- CVE-2026-100770:DOM の use-after-free によるサンドボックスのエスケープ:コンテンツプロセスコンポーネント。
- CVE-2026-100771:DOM: Streams コンポーネントにおける定義されていない動作。
- CVE-2026-100772: DOM の Core および HTML コンポーネントのメモリ解放後使用 (Use-After-Free)。
- CVE-2026-100773:Storage: IndexedDB コンポーネントの use-after-free。
- CVE-2026-100774: DOM の Core および HTML コンポーネントのメモリ解放後使用 (Use-After-Free)。
- CVE-2026-100775:Graphics コンポーネントのサンドボックスエスケープ。
- CVE-2026-100776: JavaScript: WebAssembly コンポーネントのメモリ解放後使用 (Use After Free)。
- CVE-2026-100777:Graphics: Canvas2D コンポーネントの use-after-free。
- CVE-2026-100778:DOM の use-after-free によるサンドボックスのエスケープ:コア &; HTML コンポーネント。
- CVE-2026-100779:XSLT コンポーネントの use-after-free。
- CVE-2026-100780: DOM の Core および HTML コンポーネントのメモリ解放後使用 (Use-After-Free)。
- CVE-2026-100781:Graphics: WebRender コンポーネントの境界条件が正しくないことによるサンドボックスエスケープ。
- CVE-2026-100782:Graphics コンポーネントの不適切な境界条件による権限昇格。
- CVE-2026-100783:オーディオ/ビデオコンポーネントの初期化されていないメモリ。
- CVE-2026-100784: Layout: Text および Fonts コンポーネントのメモリ解放後使用 (Use After Free)。
- CVE-2026-100785: DOM の Core および HTML コンポーネントのメモリ解放後使用 (Use-After-Free)。
- CVE-2026-100786:Graphics コンポーネントの use-after-free によるサンドボックスのエスケープ。
- CVE-2026-100787:XUL コンポーネントのサンドボックスエスケープ。
- CVE-2026-100788: JavaScript: WebAssembly コンポーネントの無効なポインター。
- CVE-2026-100789:Graphics: Canvas2D コンポーネントの use-after-free。
- CVE-2026-100790:XSLT コンポーネントの use-after-free。
- CVE-2026-100791: DOM の Core および HTML コンポーネントのメモリ解放後使用 (Use-After-Free)。
- CVE-2026-100792: JavaScript: WebAssembly コンポーネントの JIT ミスコンパイル。
- CVE-2026-100794:国際化コンポーネントの不適切な境界条件によるサンドボックスエスケープ。
- CVE-2026-100797:Graphics: WebRender コンポーネントの use-after-free による権限昇格。
- CVE-2026-100798:Storage: Quota Manager コンポーネントにおける暗号の誤用。
- CVE-2026-100800: Disability Access API コンポーネントの use-after-free によるサンドボックスエスケープ。
- CVE-2026-100801:DLL サービスコンポーネントの権限昇格。
- CVE-2026-100803:WebExtensions コンポーネントの同一生成元ポリシーのバイパス。
- CVE-2026-100806:Graphics: WebGPU コンポーネントの初期化されていないメモリ。
- CVE-2026-100807:DOM: Service Workers コンポーネントの権限昇格。
- CVE-2026-100808:DOM: Service Workers コンポーネントでの緩和策バイパス。
- CVE-2026-100809:DevTools コンポーネントの同一生成元ポリシーバイパス。
- CVE-2026-100811:DOM の use-after-free によるサンドボックスのエスケープ:コア &; HTML コンポーネント。
- CVE-2026-100812:Graphics コンポーネントのサービス拒否。
- CVE-2026-100814: JavaScript Engine: JIT コンポーネントでの不適切な境界条件。
- CVE-2026-100815:CSS 解析および計算コンポーネントの use-after-free。
- CVE-2026-100816:DOM のサイト分離の問題:ネットワーキングコンポーネント。
- CVE-2026-100818:Widget: Gtk コンポーネントの use-after-free によるサンドボックスエスケープ。
- CVE-2026-100819:XPCOM コンポーネントの不適切な境界条件によるサンドボックスエスケープ。
- CVE-2026-100820:アドレスバーコンポーネントの権限昇格。
- CVE-2026-100821:Panning および Zooming コンポーネントのサイト分離の問題。
- CVE-2026-100822:Networking: HTTP コンポーネントでのなりすましの問題。
- CVE-2026-100824:Places コンポーネントでの権限昇格。
- CVE-2026-100825:JavaScript Engine: JIT コンポーネントの use-after-free。
- CVE-2026-100826:Storage:StorageManager コンポーネントにおけるサービス拒否。
- CVE-2026-100828:Bookmarks & History コンポーネントの緩和策バイパス。
- CVE-2026-100829: DOM: Security コンポーネントの軽減バイパス。
- CVE-2026-100830:DOM: ナビゲーションコンポーネントの緩和策バイパス。
- CVE-2026-100831:DOM の use-after-free: UI イベントとフォーカスの処理コンポーネント。
- CVE-2026-100832:Graphics: Canvas2D コンポーネントの use-after-free。

Tenable は、前述の記述ブロックを SUSE セキュリティアドバイザリから直接抽出しています。

Nessus はこれらの問題をテストしておらず、代わりにアプリケーションが自己報告するバージョン番号にのみ依存していることに注意してください。

ソリューション

影響を受けるパッケージを更新してください。

参考資料

https://bugzilla.suse.com/1282929

https://www.suse.com/security/cve/CVE-2026-100756

https://www.suse.com/security/cve/CVE-2026-100757

https://www.suse.com/security/cve/CVE-2026-100758

https://www.suse.com/security/cve/CVE-2026-100759

https://www.suse.com/security/cve/CVE-2026-100760

https://www.suse.com/security/cve/CVE-2026-100762

https://www.suse.com/security/cve/CVE-2026-100765

https://www.suse.com/security/cve/CVE-2026-100766

https://www.suse.com/security/cve/CVE-2026-100767

https://www.suse.com/security/cve/CVE-2026-100769

https://www.suse.com/security/cve/CVE-2026-100770

https://www.suse.com/security/cve/CVE-2026-100771

https://www.suse.com/security/cve/CVE-2026-100772

https://www.suse.com/security/cve/CVE-2026-100773

https://www.suse.com/security/cve/CVE-2026-100774

https://www.suse.com/security/cve/CVE-2026-100775

https://www.suse.com/security/cve/CVE-2026-100776

https://www.suse.com/security/cve/CVE-2026-100777

https://www.suse.com/security/cve/CVE-2026-100778

https://www.suse.com/security/cve/CVE-2026-100779

https://www.suse.com/security/cve/CVE-2026-100780

https://www.suse.com/security/cve/CVE-2026-100781

https://www.suse.com/security/cve/CVE-2026-100782

https://www.suse.com/security/cve/CVE-2026-100783

https://www.suse.com/security/cve/CVE-2026-100784

https://www.suse.com/security/cve/CVE-2026-100785

https://www.suse.com/security/cve/CVE-2026-100786

https://www.suse.com/security/cve/CVE-2026-100787

https://www.suse.com/security/cve/CVE-2026-100788

https://www.suse.com/security/cve/CVE-2026-100789

https://www.suse.com/security/cve/CVE-2026-100790

https://www.suse.com/security/cve/CVE-2026-100791

https://www.suse.com/security/cve/CVE-2026-100792

https://www.suse.com/security/cve/CVE-2026-100794

https://www.suse.com/security/cve/CVE-2026-100797

https://www.suse.com/security/cve/CVE-2026-100798

https://www.suse.com/security/cve/CVE-2026-100800

https://www.suse.com/security/cve/CVE-2026-100801

https://www.suse.com/security/cve/CVE-2026-100803

https://www.suse.com/security/cve/CVE-2026-100806

https://www.suse.com/security/cve/CVE-2026-100807

https://www.suse.com/security/cve/CVE-2026-100808

https://www.suse.com/security/cve/CVE-2026-100809

https://www.suse.com/security/cve/CVE-2026-100811

https://www.suse.com/security/cve/CVE-2026-100812

https://www.suse.com/security/cve/CVE-2026-100814

https://www.suse.com/security/cve/CVE-2026-100815

https://www.suse.com/security/cve/CVE-2026-100816

https://www.suse.com/security/cve/CVE-2026-100818

https://www.suse.com/security/cve/CVE-2026-100819

https://www.suse.com/security/cve/CVE-2026-100820

https://www.suse.com/security/cve/CVE-2026-100821

https://www.suse.com/security/cve/CVE-2026-100822

https://www.suse.com/security/cve/CVE-2026-100824

https://www.suse.com/security/cve/CVE-2026-100825

https://www.suse.com/security/cve/CVE-2026-100826

https://www.suse.com/security/cve/CVE-2026-100828

https://www.suse.com/security/cve/CVE-2026-100829

https://www.suse.com/security/cve/CVE-2026-100830

https://www.suse.com/security/cve/CVE-2026-100831

https://www.suse.com/security/cve/CVE-2026-100832

https://www.suse.com/security/cve/CVE-2026-96869

プラグインの詳細

深刻度: Critical

ID: 362524

ファイル名: openSUSE-2026-21980-1.nasl

バージョン: 1.2

タイプ: Local

エージェント: unix

公開日: 2026/10/2

更新日: 2026/10/2

サポートされているセンサー: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

リスク情報

VPR

リスクファクター: Medium

スコア: 5

パーセンタイル: 93.18

CVSS v2

リスクファクター: Critical

基本値: 10

現状値: 7.4

ベクトル: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS スコアのソース: CVE-2026-100832

CVSS v3

リスクファクター: Critical

基本値: 9.8

現状値: 8.5

ベクトル: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

現状ベクトル: CVSS:3.0/E:U/RL:O/RC:C

CVSS スコアのソース: CVE-2026-100788

脆弱性情報

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:mozillafirefox-branding-upstream, p-cpe:/a:novell:opensuse:mozillafirefox-devel, p-cpe:/a:novell:opensuse:mozillafirefox-translations-common, p-cpe:/a:novell:opensuse:mozillafirefox-translations-other, p-cpe:/a:novell:opensuse:mozillafirefox

必要な KB アイテム: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

エクスプロイトの容易さ: No known exploits are available

パッチ公開日: 2026/9/30

脆弱性公開日: 2026/9/29

参照情報

CVE: CVE-2026-100756, CVE-2026-100757, CVE-2026-100758, CVE-2026-100759, CVE-2026-100760, CVE-2026-100762, CVE-2026-100765, CVE-2026-100766, CVE-2026-100767, CVE-2026-100769, CVE-2026-100770, CVE-2026-100771, CVE-2026-100772, CVE-2026-100773, CVE-2026-100774, CVE-2026-100775, CVE-2026-100776, CVE-2026-100777, CVE-2026-100778, CVE-2026-100779, CVE-2026-100780, CVE-2026-100781, CVE-2026-100782, CVE-2026-100783, CVE-2026-100784, CVE-2026-100785, CVE-2026-100786, CVE-2026-100787, CVE-2026-100788, CVE-2026-100789, CVE-2026-100790, CVE-2026-100791, CVE-2026-100792, CVE-2026-100794, CVE-2026-100797, CVE-2026-100798, CVE-2026-100800, CVE-2026-100801, CVE-2026-100803, CVE-2026-100806, CVE-2026-100807, CVE-2026-100808, CVE-2026-100809, CVE-2026-100811, CVE-2026-100812, CVE-2026-100814, CVE-2026-100815, CVE-2026-100816, CVE-2026-100818, CVE-2026-100819, CVE-2026-100820, CVE-2026-100821, CVE-2026-100822, CVE-2026-100824, CVE-2026-100825, CVE-2026-100826, CVE-2026-100828, CVE-2026-100829, CVE-2026-100830, CVE-2026-100831, CVE-2026-100832, CVE-2026-96869

IAVA: 2026-A-1076