参照: Official alpine advisory, NVD, CVE.org · CVE 詳細
Freshness: no update timestamp found; verify against the upstream OS advisory manually.
CVE-2026-0886: 3 source package rows (firefox, firefox-esr, thunderbird); 274 state rows across 2 repos (3.23-community, edge-community); fixed 0, open 274.
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.