Leap 16.0 / Firefox and LibreOffice updates

It’s a bit strange, because since I wrote that there is also a LibreOffice update problem:
forums.opensuse.org/t/unupdated-libreoffice-security-issue/194110

Firefox ESR no longer seems to be updated:
www.firefox.com/en-US/firefox/152.0.1/releasenotes

While the problem seemed to be fixed by taking the Tumbleweed version on Leap 16.0:
forums.opensuse.org/t/firefox-update-or-not/192461

Firefox-ESR is actual on Version 140.12

ESR = Extended Support Release different to Firefox.

See:

stephan@linux64:~> lsb-release -id && firefox -v
Distributor ID: openSUSE
Description:    openSUSE Leap 16.0
Mozilla Firefox 140.11.0esr
stephan@linux64:~> 

So maybe there is a update to Version 140.12 on its way, I don’t know.

1 Like

I’m sorry, I pointed you to the wrong page:
www.firefox.com/en-US/firefox/140.12.0/releasenotes

The Updates for openSuse are often a little bit later because openSUSE is using some build specials as @malcolmmacvean says in the other post of you. So wait or ask on the mailing list.
This is not the right place to talk about the build process of openSUSE.

MozillaThunderbird (=thunderbird-esr) is at 140.10.0 in Leap 16, while the actual release is 140.12.0. This is 2 months and not “a little bit” later, I would call it unmaintained.

2 Likes

Even TW is on Thunderbird 140.11
The maintainers would be for sure happy about every helping hand.

I filed https://bugzilla.opensuse.org/show_bug.cgi?id=1259678 for a missing thunderbird update earlier, which resulted in one update. What do you expect me to do, nagging the maintainer by filing a bug report after every upstream release?

2 Likes

As the (unpaid) maintainers are not sitting all the day in front of the different upstream projects and waiting for updates, one can at least give them a ping via a bugreport.

And honestly, with all due respect, instead of claiming that FF/TB is unmaintained on openSUSE, you can do at least a basic research.

Use as example pkgs.org as database and inform yourself. openSUSE is one of the few distributions with the highest TB/FF ESR version compared to others. And in the list there is atm only one distribution (Slack) which ships TB 140.12

Two machines running leap 16
and ff 140.11.0esr (64-Bit)

georg@heka:~> zypper patch-info openSUSE-Leap-16.0-795
Repository-Daten werden geladen...
Installierte Pakete werden gelesen...


Informationen zu Patch openSUSE-Leap-16.0-795:
----------------------------------------------
Repository       : repo-oss (16.0)
Name             : openSUSE-Leap-16.0-795
Version          : 1
Arch             : noarch
Anbieter         : maintenance@opensuse.org
Status           : angewendet
Kategorie        : security
Schweregrad      : important
Erstellt am      : Fr 22 Mai 2026 15:34:55 CEST
Interaktiv       : ---
Zusammenfassung  : Security update for MozillaFirefox
Beschreibung     : 
    This update for MozillaFirefox fixes the following issues

    - Update to Firefox Extended Support Release 140.11.0 ESR MFSA 2026-48 (bsc#1265212).

    MFSA 2026-48:

    - CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component.
    - CVE-2026-8391: Other issue in the JavaScript Engine component.
    - CVE-2026-8401: Sandbox escape in the Profile Backup component.
    - CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component.
    - CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component.
    - CVE-2026-8949: Integer overflow in the Widget: Win32 component.
    - CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component.
    - CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component.
    - CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component.
    - CVE-2026-8955: Privilege escalation in the DOM: Workers component.
    - CVE-2026-8956: Integer overflow in the Networking: JAR component.
    - CVE-2026-8957: Privilege escalation in the Enterprise Policies component.
    - CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component.
    - CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
    - CVE-2026-8961: Spoofing issue in the Form Autofill component.
    - CVE-2026-8962: Mitigation bypass in the DOM: Security component.
    - CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component.
    - CVE-2026-8970: Privilege escalation in the Security component.
    - CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151.
    - CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151.
Bereitstellungen : patch:openSUSE-Leap-16.0-795 = 1
Konflikte        : [21]
    MozillaFirefox.aarch64 < 140.11.0-160000.1.1
    MozillaFirefox.noarch < 140.11.0-160000.1.1
    MozillaFirefox-branding-upstream.aarch64 < 140.11.0-160000.1.1
    MozillaFirefox-branding-upstream.noarch < 140.11.0-160000.1.1
    MozillaFirefox-devel < 140.11.0-160000.1.1
    MozillaFirefox-translations-common.aarch64 < 140.11.0-160000.1.1
    MozillaFirefox-translations-common.noarch < 140.11.0-160000.1.1
    MozillaFirefox-translations-other.aarch64 < 140.11.0-160000.1.1
    MozillaFirefox-translations-other.noarch < 140.11.0-160000.1.1
    MozillaFirefox.ppc64le < 140.11.0-160000.1.1
    MozillaFirefox-branding-upstream.ppc64le < 140.11.0-160000.1.1
    MozillaFirefox-translations-common.ppc64le < 140.11.0-160000.1.1
    MozillaFirefox-translations-other.ppc64le < 140.11.0-160000.1.1
    MozillaFirefox.s390x < 140.11.0-160000.1.1
    MozillaFirefox-branding-upstream.s390x < 140.11.0-160000.1.1
    MozillaFirefox-translations-common.s390x < 140.11.0-160000.1.1
    MozillaFirefox-translations-other.s390x < 140.11.0-160000.1.1
    MozillaFirefox.x86_64 < 140.11.0-160000.1.1
    MozillaFirefox-branding-upstream.x86_64 < 140.11.0-160000.1.1
    MozillaFirefox-translations-common.x86_64 < 140.11.0-160000.1.1
    MozillaFirefox-translations-other.x86_64 < 140.11.0-160000.1.1

georg@heka:~> 

Yes, ACK, so far.

I like to compare against Debian (stable) due to “reasons”(*)

https://packages.debian.org/search?keywords=firefox-esr&searchon=names&exact=1&suite=all&section=all

trixie (stable) (web): Webbrowser Mozilla Firefox mit verlängerter Wartung (Extended Support Release, ESR)
140.12.0esr-1~deb13u1 [security]: amd64 arm64 armhf i386 ppc64el riscv64 s390x

https://packages.debian.org/search?keywords=thunderbird&searchon=names&exact=1&suite=all&section=all

trixie (stable) (mail): Mail/News-Client mit integriertem Spam-Filter und Unterstützung für RSS/Chat
1:140.12.0esr-1~deb13u1 [security]: amd64 arm64 i386 ppc64el riscv64

And Debian (stable) is said to be staling…

(*):

  • I like to compare openSUSE against Debian generally due to “reasons”
  • Leap against Debian (stable)
  • it’s not about TW (as for openSUSE)…
  • it’s not about some other distros to be compared against (@hui showed that openSUSE is not that bad — but there are others (being up-to-date)!)

But anyway, this topic has been shown up several times… It’s probably useless to discuss it here again and again. Maybe, it could be worth to get — kindly and friendly — in touch with related maintainers. As for me, I once was in touch with some of Mozilla OBS guys. But so far, I haven’t completely understood the actual difference between maintenance of Mozilla OBS and pool Mozilla. I guess it is about something that Mozilla OBS is the dev repo for TW (only) — and Leap is derived vom SLE (on the opposite)… If Leap would get packages from there, it actually could be faster. But it seems, this is mainly just for TW — and the packages for Leap are there (in the repo), because it is possible (not because it is a real process chain for it that is actively used — building for different platforms and architectures is just enabled on: if it then build properly for each setting, fine).

Look at post #2, Firefox ESR is on 140.11, one week behind 140.12…

As far as I can see, MozillaFirefox comes from the SLE code base and has been updated mostly a few days after upstream release. I certainly did not question your statement regarding MozillaFirefox.

MozillaThunderbird on the other hand is maintained by openSUSE and lags now five releases behind upstream.
140.10.0 → 140.10.1 → 140.10.2 → 140.11.0 → 140.11.1 → 140.12.0
I can’t remember anything similar with Leap 15.x.
If there is a better word for this than unmaintained, please let me know.

1 Like

@giuschwim you can always put your skills to work and help?

And so the world rolls on… Don’t forget it’s Summer holiday time, the openSUSE Conference is about to begin etc.

Realistically, is there a potential security flaw being exposed, are you affected, have you tested to see if you can duplicate etc…

If it’s just minor bug fixes that may or may not affect you, it really isn’t the end of the world…

You may take a look at flathub.

georg@heka:~> flatpak search Firefox
Name           Beschreibung                            Anwendungskennung          Version        Zweig         Gegenstellen
Firefox        Fast, Private & Safe Web Browser        org.mozilla.firefox        152.0.2        stable        flathub
georg@heka:~> flatpak search Thunderbird
Name        Beschreibung                                                  Anwendungskennung        Version     Zweig  Gegenstellen
Thunderbir… Thunderbird is a free and open source email, newsfeed, chat,… …mozilla.thunderbird_esr 140.12.0esr stable flathub
Thunderbird Thunderbird is a free and open source email, newsfeed, chat,… org.mozilla.thunderbird  152.0       stable flathub
georg@heka:~> 

Duh! Oh, please!

There are up to date packages of thunderbird-esr in the OBS Mozilla project, which seems to be “semi-official”, because the maintainers are the same as of the official Mozilla factory packages.
The question is, why are they not used for Leap 16? I suspect is has to do with the transition of source management to git.

AFAICS, partly yes/no…

Compare https://src.opensuse.org/pool/MozillaFirefox/commits/branch/factory
to https://src.opensuse.org/pool/MozillaFirefox/commits/branch/slfo-main

and https://src.opensuse.org/pool/MozillaThunderbird/commits/branch/factory
to https://src.opensuse.org/pool/MozillaThunderbird/commits/branch/leap-16.0

There are some obvious differences!

(text formatting (bold) by me)

1 Like

missing: https://src.opensuse.org/pool/firefox-esr/commits/branch/factory

Thanks for your in depth clarification.
My installed version of Thunderbird is MozillaThunderbird-140.10.0-bp160.1.1.x86_64.
As far as I know you can tell by the extension bp160 that it’s not derived from SLE.

I don’t know exactly:

At least, you can see:
For Leap, Thunderbird ESR updates up to 128 have done by Wolfgang Rosenauer (also very active for Mozilla otherwise) — whereas since 140 ESR by Yoshio_Sato.

(text formatting (bold) by me)

It was just this Wolfgang Rosenauer back then and it was a very nice and pleasant experience (does work frequently and often, nice talking to). But I don’t know Yoshio_Sato (as I haven’t at all before!).

Please, feel free.

For Mozilla OBS resp. factory, so for TW, Thunderbird ESR 140.12.0 has been released by Wolfgang Rosenauer — whereas for Leap by Yoshio_Sato it is still missing (as 140.10.1, 140.10.2, 140.11.0, 140.11.1 are since that 140.10.0!).

Oh, sorry. Not payed attention to -bp… What does it actually tell?