firefox140: update to 140.17
Mozilla Foundation Security Advisory 2026-99
Security Vulnerabilities fixed in Firefox ESR 140.17
Announced
September 29, 2026
Impact
high
Products
Firefox ESR
Fixed in
Firefox ESR 140.17
Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component
Reporter
[469 lines not shown]
firefox153: update to 153.4
Mozilla Foundation Security Advisory 2026-100
Security Vulnerabilities fixed in Firefox ESR 153.4
Announced
September 29, 2026
Impact
high
Products
Firefox ESR
Fixed in
Firefox ESR 153.4
Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component
Reporter
[678 lines not shown]
fuse-emulator-utils: updated to 1.5.0
1.5.0
* listbasic
* Support extracting BASIC listings from Microdrive cartridge
images (Fredrick Meunier).
* mdrlist
* New utility to list the contents of an MDR Microdrive cartridge
image (Fredrick Meunier).
* fmfconv
* Refresh flashing cells when the FMF flash phase changes (bug 526)
(thanks, Alberto Garcia) (Fredrick Meunier).
* rzxdump
* Display the contents of compressed input blocks (Fredrick
Meunier).
[16 lines not shown]
fuse-emulator: updated to 1.10.0
* Emulation core improvements:
* Expand automatic tape-loader detection and acceleration for
Microprose, Software Projects, Gremlin 2 and Movieload loaders
(fixes bugs 396, 429 and 430) (thanks, Philip Kendall)
(Fredrick Meunier).
* Improve automatic tape playback for custom loaders, allowing Basil
the Great Mouse Detective, Viz: The Computer Game, Moonlighter and
Trzy Wymiary to load without manual tape control (fixes bug 433
and part of bug 218) (Fredrick Meunier).
* Preserve the complete tape signal state when switching from ROM
traps to custom loaders, allowing Bomb Jack and similar loaders to
continue correctly (fixes bug 333 and part of bug 310)
(Fredrick Meunier).
* Avoid accelerating the Technician Ted loader (fixes bug 55)
(Fredrick Meunier).
* Do not automatically restart rewound tapes at end of tape, making
it easier to change sides in multi-side games such as Echelon
[75 lines not shown]
libspectrum: updated to 1.7.0
1.7.0
* Make tape playback own signal polarity and return absolute levels for
live and cursor playback, with atomic cursor state operations
(Fredrick Meunier).
* Add a resolved-file abstraction for accessing compressed and
uncompressed files (part of bugs 507 and 192) (Fredrick Meunier,
thanks Gergely Szasz and Bernat).
* Add RZX playback input cursor and creator metadata APIs (Fredrick
Meunier).
* Add structured accessors for microdrive block headers, record
descriptors, data and checksums (Fredrick Meunier).
* Require C11 or later (Fredrick Meunier).
[15 lines not shown]
py-nanobind: updated to 3.1.0
3.1.0 (Sep 28, 2026)
- Python subclasses can now combine one nanobind base with additional
:ref:`Python mixins <python_mixins>`, including cooperative ``super()`` calls
on CPython and PyPy. Inheriting from multiple nanobind bases remains
unsupported.
- The low-level instance API gained :cpp:func:`nb::inst_python_derived()
<inst_python_derived>`, which reports whether a nanobind instance belongs to
a Python subclass of the bound type.
- Added new low-level functions :cpp:func:`nb::keep_alive_obj() <keep_alive_obj>` and
:cpp:func:`nb::keep_alive_cb() <keep_alive_cb>`, which expose the mechanism behind
the :cpp:class:`nb::keep_alive <keep_alive>` annotation.
- The new function :cpp:func:`intrusive_counter::ref_count()` returns the
reference count of an intrusively reference-counted object while it is owned by C++.
- Fixed stale trampoline override caches on PyPy. Changing an attribute of a
nanobind type now correctly invalidates the caches of its Python subclasses.
- The ``std::map``/``std::unordered_map`` and ``std::set`` type casters can
[5 lines not shown]
py-pygraphviz: updated to 2.0.2
2.0.2
MAINT: simplify compressed filename handling
CI: Update twine requirement from >=4.0 to >=7.0.0
CI: Update pre-commit requirement from >=4.1 to >=4.6.1
CI: Bump actions/setup-python from 6 to 7
Support Python 3.15
haproxy: updated to 3.4.6
3.4.6
- MINOR: log: pass the input end to the _lf_encode_bytes() byte encoders
- MINOR: log: add the +utf8 encoding option to let valid UTF-8 pass
- BUG/MAJOR: mux_quic: fix potential crash on RESET_STREAM receive
- BUG/MEDIUM: sink: reconnect attempt not working after session lasted more than ~25 days
- BUG/MEDIUM: server: skip log backend addr checks for internal proxies
- REGTESTS: log: check that a ring's internal server may target a UNIX socket
3.4.5
- BUG/MINOR: cache: Manage collisions on primary key
- BUG/MINOR: cache: Seed cache primary hash
- OPTIM: server: remember the lowest known unused server ID
- BUG/MEDIUM: mux-spop: Properly handle parsing of split HELLO/DISCONNECT frames
- BUG/MINOR: payload: fix the cipher_len bound check in smp_client_hello_parse()
- BUG/MINOR: payload: bound ClientHello extension lists by the extension length
- BUG/MEDIUM: quic: crash on key update phase change after a failed one
- BUG/MINOR: quic: late packets of the first key phase are dropped
[77 lines not shown]
py-isort: updated to 9.0.2
9.0.2
Fixes
Preserve blank lines before comment-only sections
Preserve trailing-comma layout when sorting reexports
fix: treat EOF on stdin as 'quit' in --interactive prompt
Fix multi_line_output=10 emitting unparsable code around trailing comments
Stop configuration discovery at Git worktree boundaries
fix: preserve trailing comments when sorting literals
Preserve LF stdin output on Windows
Handle star imports better when using parenthesis
Sort unwrapped lines in force_sort_within_sections
Preserve file line endings when sorting reexports
Fix float_to_top hoisting indented semicolon imports
Preserve CRLF blank lines during float-to-top preprocessing
mypy: type-check tests and use pathlib fixtures
py-blockbuster: updated to 1.5.28
1.5.28
Fix AttributeError on reads from file objects without a fileno
Fix compatibility with Python 3.15
Support Python 3.15.0rc2
ccache: updated to 4.14.1
4.14.1
New deliverables
Added musl static binary release for Linux s390x.
Bug fixes
Restored storage helper lock compatibility with ccache versions earlier than 4.14.
Fixed lookup of GCC 9+ profile data for object files in subdirectories and added support for GCC’s -fprofile-partial-training option.
Fixed the output location of files produced by GCC’s -fdump-ipa-clones option.
Fixed hashing of C++20 module files found via Clang’s -fprebuilt-module-path option, preventing false cache hits when a module changes.
Made ccache reject clang-cl’s /clang: option and MSVC’s /FA and /Fa options instead of potentially caching compilations incorrectly.
Fixed cleanup of temporary response files on Windows.
Build improvements
[7 lines not shown]
appstream: updated to 1.2.1
1.2.1
Features:
* curl: Include "libcurl" in UA string so AI bot protection hits us less
* compose: Permit changing the downloader user agent
* compose: Try to guess what media we actually downloaded if processing failed
* Add support for elogind
Bugfixes:
* meson: Make sed command cross-platform friendly
* meson: Don't use any absolute include path to find libstemmer.h
* system-info: Avoid overflow in physical memory total on 32-bit systems
* compose: Flag a missing ffprobe as its own error
* docs: Work around a rare DAPS race condition when building documentation
* Resolve or skip failing tests on riscv64 & s390x
* validator: Fix validation of `references` elements
* tests: Relax fontconfig orthography data check for 2.18.3 bug
[3 lines not shown]