View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2026-0885 severity important: SUSE including 47 source package names (2.2.0-4.49:libopenssl3-3.1.4-slfo.1.1_5.1, 2.2.0-4.50:libopenssl3-3.1.4-slfo.1.1_5.1, …), 215 product×package rows across 87 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Container suse/sl-micro/6.0/base-os-container, … (87 product lines)): Fixed 211, First Fixed 4.
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.