Slackware 1279 Published by

Slackware Linux released security updates for libssh and mozilla-firefox affecting versions 15.0 and -current to patch critical vulnerabilities identified in CVE-2026-15370 through CVE-2026-59849 alongside dozens of additional Firefox advisories. The libssh upgrade resolves a stack buffer overflow in SFTP server longname construction, denial of service flaws triggered by oversized read lengths and unchecked fork failures, an information disclosure via ProxyCommand username expansion, and an integrity downgrade linked to OpenSSL AES-GCM tag verification. Mozilla-Firefox receives version 140.13.0esr with security fixes and improvements based on upstream release notes, covering patches for numerous CVEs that address memory safety errors and privilege escalation risks across the browser engine.

libssh (SSA:2026-202-01)
mozilla-firefox (SSA:2026-202-02)




libssh (SSA:2026-202-01)



libssh (SSA:2026-202-01)

New libssh packages are available for Slackware 15.0 and -current to
fix security issues.

Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/libssh-0.11.5-i586-1_slack15.0.txz: Upgraded.
This update fixes security issues:
Stack buffer overflow in SFTP server longname construction.
Denial of service via zero advertised channel packet size.
Denial of service via oversized SFTP read length.
Denial of service via unchecked ProxyCommand fork() failure.
Information disclosure via ProxyCommand %r username expansion.
Integrity downgrade via OpenSSL AES-GCM tag verification.
Denial of service via SFTP responses with unknown request IDs.
Denial of service via automatic certificate authentication loop.
Use-after-free via data callbacks on closed channels.
Zero-initialize every ssh_string.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-15370
https://www.cve.org/CVERecord?id=CVE-2026-59843
https://www.cve.org/CVERecord?id=CVE-2026-59844
https://www.cve.org/CVERecord?id=CVE-2026-59845
https://www.cve.org/CVERecord?id=CVE-2026-59846
https://www.cve.org/CVERecord?id=CVE-2026-59847
https://www.cve.org/CVERecord?id=CVE-2026-59848
https://www.cve.org/CVERecord?id=CVE-2026-59849
https://www.cve.org/CVERecord?id=CVE-2026-59850
(* Security fix *)
+--------------------------+

Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
( http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libssh-0.11.5-i586-1_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libssh-0.11.5-x86_64-1_slack15.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libssh-0.12.1-i686-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libssh-0.12.1-x86_64-1.txz

MD5 signatures:
+-------------+

Slackware 15.0 package:
fc3aa3b43df45ca2f56b7ce893349004 libssh-0.11.5-i586-1_slack15.0.txz

Slackware x86_64 15.0 package:
f7e6b1f037fec2be10fb188b148f52a1 libssh-0.11.5-x86_64-1_slack15.0.txz

Slackware -current package:
7c71c6735698fa981b7bc002ce6b60c5 l/libssh-0.12.1-i686-1.txz

Slackware x86_64 -current package:
5cbced800f2425577eec6ace1c9b12ea l/libssh-0.12.1-x86_64-1.txz

Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg libssh-0.11.5-i586-1_slack15.0.txz

+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key


mozilla-firefox (SSA:2026-202-02)



mozilla-firefox (SSA:2026-202-02)

New mozilla-firefox packages are available for Slackware 15.0 and -current to
fix security issues.

Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/mozilla-firefox-140.13.0esr-i686-1_slack15.0.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/140.13.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2026-70/
https://www.cve.org/CVERecord?id=CVE-2026-15718
https://www.cve.org/CVERecord?id=CVE-2026-15719
https://www.cve.org/CVERecord?id=CVE-2026-16349
https://www.cve.org/CVERecord?id=CVE-2026-16350
https://www.cve.org/CVERecord?id=CVE-2026-16362
https://www.cve.org/CVERecord?id=CVE-2026-16351
https://www.cve.org/CVERecord?id=CVE-2026-16352
https://www.cve.org/CVERecord?id=CVE-2026-16363
https://www.cve.org/CVERecord?id=CVE-2026-16353
https://www.cve.org/CVERecord?id=CVE-2026-16354
https://www.cve.org/CVERecord?id=CVE-2026-16368
https://www.cve.org/CVERecord?id=CVE-2026-16369
https://www.cve.org/CVERecord?id=CVE-2026-16355
https://www.cve.org/CVERecord?id=CVE-2026-16356
https://www.cve.org/CVERecord?id=CVE-2026-16357
https://www.cve.org/CVERecord?id=CVE-2026-16371
https://www.cve.org/CVERecord?id=CVE-2026-16374
https://www.cve.org/CVERecord?id=CVE-2026-16375
https://www.cve.org/CVERecord?id=CVE-2026-16377
https://www.cve.org/CVERecord?id=CVE-2026-16379
https://www.cve.org/CVERecord?id=CVE-2026-16358
https://www.cve.org/CVERecord?id=CVE-2026-16381
https://www.cve.org/CVERecord?id=CVE-2026-16383
https://www.cve.org/CVERecord?id=CVE-2026-16387
https://www.cve.org/CVERecord?id=CVE-2026-16390
https://www.cve.org/CVERecord?id=CVE-2026-16391
https://www.cve.org/CVERecord?id=CVE-2026-16359
https://www.cve.org/CVERecord?id=CVE-2026-16396
https://www.cve.org/CVERecord?id=CVE-2026-16405
https://www.cve.org/CVERecord?id=CVE-2026-16412
(* Security fix *)
+--------------------------+

Where to find the new packages:
+-----------------------------+

Thanks to the friendly folks at the OSU Open Source Lab
( http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-firefox-140.13.0esr-i686-1_slack15.0.txz

Updated package for Slackware x86_64 15.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-firefox-140.13.0esr-x86_64-1_slack15.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/mozilla-firefox-140.13.0esr-i686-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/mozilla-firefox-140.13.0esr-x86_64-1.txz

MD5 signatures:
+-------------+

Slackware 15.0 package:
eaf321081c407997e739796d814cd7a1 mozilla-firefox-140.13.0esr-i686-1_slack15.0.txz

Slackware x86_64 15.0 package:
75d5433b6bf64c35b1b502a526ed55a9 mozilla-firefox-140.13.0esr-x86_64-1_slack15.0.txz

Slackware -current package:
5f2bd631d2a91014e2213eb22595d425 xap/mozilla-firefox-140.13.0esr-i686-1.txz

Slackware x86_64 -current package:
c8ef4cb4a1e4669f7f2f2d70349b0bf1 xap/mozilla-firefox-140.13.0esr-x86_64-1.txz

Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg mozilla-firefox-140.13.0esr-i686-1_slack15.0.txz

+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key