suse · CVE-2026-0885

Quick triage

Priority: high Published: 2026-03-05 00:19:50 UTC Updated: 2026-04-16 13:39:29 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-0885 severity important: SUSE including 47 source package names (2.2.0-4.49:libopenssl3-3.1.4-slfo.1.1_5.1, 2.2.0-4.50:libopenssl3-3.1.4-slfo.1.1_5.1, …), 215 product×package rows across 87 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Container suse/sl-micro/6.0/base-os-container, … (87 product lines)): Fixed 211, First Fixed 4.

Description:

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

cvelogic Threat Intelligence