Amazon Linux 2:firefox,--advisory ALAS2FIREFOX-2026-063 (ALASFIREFOX-2026-063)

medium Nessus Plugin ID 337223

概要

遠端 Amazon Linux 2 主機缺少安全性更新。

說明

遠端主機上安裝的 Firefox 版本比 140.13.0-1 舊。因此,它會受到 ALAS2FIREFOX-2026-063 公告中所提及的多個弱點影響。

DOM: Navigation 元件中的同源原則繞過。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16349)

音訊/視訊: cubeb 元件中的邊界條件不正確。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16350)

由於 DOM: Navigation 元件中的釋放後使用而導致的沙箱逸出。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16351)

Disability Access API 元件中由於釋放後使用而導致的沙箱逸出問題。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16352)

DOM: Bindings (WebIDL) 元件中的指標無效。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16353)

Graphics: ImageLib 元件中的資訊洩漏。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16354)

JavaScript Engine: JIT 元件中的 JIT 編譯錯誤。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16355)

Disability Access API 元件中由於釋放後使用而導致的沙箱逸出問題。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16356)

Graphics 元件中的邊界條件不正確。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16357)

Graphics: WebRender 元件中的網站隔離問題。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16358)

Audio/Video: GMP 元件中的邊界條件不正確。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16359)

Firefox ESR 115.37、Firefox ESR 140.12 和 Firefox 152 中存在記憶體安全錯誤。某些錯誤顯示記憶體會遭到損毀,我們推測若有心人士有意操控,可能惡意利用其中部分錯誤執行任意程式碼。此漏洞已在 Firefox 153、Firefox ESR 115.38和 Firefox ESR 140.13中修復。(CVE-2026-16360)

Firefox ESR 115.37 和 Firefox ESR 140.12中存在記憶體安全錯誤。某些錯誤顯示記憶體會遭到損毀,我們推測若有心人士有意操控,可能惡意利用其中部分錯誤執行任意程式碼。此弱點已在 Firefox ESR 115.38 和 Firefox ESR 140.13中修正。(CVE-2026-16361)

WebRTC:Audio/Video 元件中的釋放後使用。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16362)

JavaScript: WebAssembly 元件中的 JIT 錯誤編譯。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16363)

JavaScript:WebAssembly 元件中的邊界條件不正確。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16368)

JavaScript: WebAssembly 元件中的整數溢位。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16369)

DOM 中的權限提升:導覽元件。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16371)

DevTools 中架構元件中的資訊洩漏。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16374)

Networking: HTTP 元件中的網站隔離問題。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16375)

PDF 檢視器元件中的緩解繞過。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16377)

DOM:內容處理程序元件中的權限提升。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16379)

網路:DNS 元件中的同源原則繞過。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16381)

DOM: Networking 元件中的緩解繞過。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16383)

網路元件中的網站隔離問題。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16387)

「企業原則」元件中的緩解繞過。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16390)

Storage: IndexedDB 元件中的資訊洩漏。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16391)

WebExtensions 中的權限提升。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。
(CVE-2026-16396)

Networking: WebSockets 元件中的資訊洩漏。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16405)

Firefox ESR 140.12 和 Firefox 152 中存在記憶體安全錯誤。某些錯誤顯示記憶體會遭到損毀,我們推測若有心人士有意操控,可能惡意利用其中部分錯誤執行任意程式碼。此弱點已在 Firefox 153 和 Firefox ESR 140.13中修正。(CVE-2026-16412)

在 ggml-org llama.cpp e15efe0 中發現缺陷。此弱點會影響元件 JSON-Schema-to-GBNF Conversion 的檔案 common/json-schema-to-grammar.cpp 的函式轉換。此操作會導致資源配置。攻擊者可從遠端發起攻擊。修正此問題的提取要求正在等待接受。(CVE-2026-17501)

Tenable 已直接從所測試產品的安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

執行「yum update firefox」或「yum update --advisory ALAS2FIREFOX-2026-063」以更新系統。

另請參閱

https://alas.aws.amazon.com//AL2/ALAS2FIREFOX-2026-063.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-16349.html

https://explore.alas.aws.amazon.com/CVE-2026-16350.html

https://explore.alas.aws.amazon.com/CVE-2026-16351.html

https://explore.alas.aws.amazon.com/CVE-2026-16352.html

https://explore.alas.aws.amazon.com/CVE-2026-16353.html

https://explore.alas.aws.amazon.com/CVE-2026-16354.html

https://explore.alas.aws.amazon.com/CVE-2026-16355.html

https://explore.alas.aws.amazon.com/CVE-2026-16356.html

https://explore.alas.aws.amazon.com/CVE-2026-16357.html

https://explore.alas.aws.amazon.com/CVE-2026-16358.html

https://explore.alas.aws.amazon.com/CVE-2026-16359.html

https://explore.alas.aws.amazon.com/CVE-2026-16360.html

https://explore.alas.aws.amazon.com/CVE-2026-16361.html

https://explore.alas.aws.amazon.com/CVE-2026-16362.html

https://explore.alas.aws.amazon.com/CVE-2026-16363.html

https://explore.alas.aws.amazon.com/CVE-2026-16368.html

https://explore.alas.aws.amazon.com/CVE-2026-16369.html

https://explore.alas.aws.amazon.com/CVE-2026-16371.html

https://explore.alas.aws.amazon.com/CVE-2026-16374.html

https://explore.alas.aws.amazon.com/CVE-2026-16375.html

https://explore.alas.aws.amazon.com/CVE-2026-16377.html

https://explore.alas.aws.amazon.com/CVE-2026-16379.html

https://explore.alas.aws.amazon.com/CVE-2026-16381.html

https://explore.alas.aws.amazon.com/CVE-2026-16383.html

https://explore.alas.aws.amazon.com/CVE-2026-16387.html

https://explore.alas.aws.amazon.com/CVE-2026-16390.html

https://explore.alas.aws.amazon.com/CVE-2026-16391.html

https://explore.alas.aws.amazon.com/CVE-2026-16396.html

https://explore.alas.aws.amazon.com/CVE-2026-16405.html

https://explore.alas.aws.amazon.com/CVE-2026-16412.html

https://explore.alas.aws.amazon.com/CVE-2026-17501.html

Plugin 詳細資訊

嚴重性: Medium

ID: 337223

檔案名稱: al2_ALASFIREFOX-2026-063.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/8/18

已更新: 2026/8/18

支援的感應器: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 6.9

百分位數: 96.82

CVSS v2

風險因素: Medium

基本分數: 5

時間性分數: 3.7

媒介: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS 評分資料來源: CVE-2026-17501

CVSS v3

風險因素: Critical

基本分數: 9.8

時間性分數: 8.5

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

時間媒介: CVSS:3.0/E:U/RL:O/RC:C

CVSS 評分資料來源: CVE-2026-16412

CVSS v4

風險因素: Medium

Base Score: 6.9

Threat Score: 2.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

弱點資訊

CPE: cpe:/o:amazon:linux:2, p-cpe:/a:amazon:linux:firefox

必要的 KB 項目: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

可輕鬆利用: No known exploits are available

修補程式發佈日期: 2026/8/17

弱點發布日期: 2026/7/21

參考資訊

CVE: CVE-2026-16349, CVE-2026-16350, CVE-2026-16351, CVE-2026-16352, CVE-2026-16353, CVE-2026-16354, CVE-2026-16355, CVE-2026-16356, CVE-2026-16357, CVE-2026-16358, CVE-2026-16359, CVE-2026-16360, CVE-2026-16361, CVE-2026-16362, CVE-2026-16363, CVE-2026-16368, CVE-2026-16369, CVE-2026-16371, CVE-2026-16374, CVE-2026-16375, CVE-2026-16377, CVE-2026-16379, CVE-2026-16381, CVE-2026-16383, CVE-2026-16387, CVE-2026-16390, CVE-2026-16391, CVE-2026-16396, CVE-2026-16405, CVE-2026-16412, CVE-2026-17501

IAVA: 2026-A-0755